SC-500 Microsoft Cloud and AI Security Engineer Course

  • Duration 4 days or 4 weeks
  • Price From $1,999
  • Exam Included Official Microsoft SC-500 Exam Worth $250
  • Schedule Options Full-Time (Weekdays), Part-Time (Weeknights), Part-Time (Weekends)
  • Study Mode In-person instructor-led, or live online instructor-led
  • Locations In-person in Melbourne, Sydney, Brisbane, Adelaide, Perth and Canberra, plus live online across Australia, all delivered live in real time with a trainer

Microsoft Certified Cloud and AI Security Engineer Associate certification validates protecting identities, infrastructure, databases, networking, containers and artificial intelligence workloads.

SC-500 Microsoft Cloud and AI Security Engineer Course

Microsoft Cloud and AI Security Engineer Course

The Microsoft Certified: Cloud and AI Security Engineer Associate certification is Microsoft’s current security engineer credential for Azure, hybrid and multicloud environments. It replaces the Azure Security Engineer Associate certification, which Microsoft retired on 31 August 2026. It suits security engineers, Azure administrators and cloud engineers who already work in Azure and now need to secure artificial intelligence workloads alongside traditional infrastructure.

Across four days you cover the four areas Microsoft measures. You manage identity, access and governance using Microsoft Entra ID, Privileged Identity Management, conditional access and Azure Key Vault. You secure storage accounts, Azure SQL, virtual networks, private endpoints and Azure Firewall. You secure compute, servers, containers and application platform services. You manage and monitor security posture with Microsoft Defender for Cloud, Microsoft Sentinel and Microsoft Security Copilot.

Securing artificial intelligence workloads

This is the part that separates the new credential from the old Azure security syllabus. You learn to identify data overexposure in SharePoint, assess Microsoft Copilot and agent risk using Microsoft Purview Data Security Posture Management, apply conditional access to Microsoft Entra Agent ID, configure AI Gateway and guardrails in Microsoft Foundry, and turn on Defender for AI Services in Defender for Cloud.

Where this course sits on the Microsoft security path

If cloud security is new to you, start with the SC-900 Microsoft Security, Compliance and Identity Fundamentals course, then build the Azure administration base with the AZ-104 Microsoft Azure Administrator course. Once certified, the usual next step is the SC-100 Microsoft Cybersecurity Architect course.

Replacing the AZ-500 Azure Security Engineer certification

Microsoft retired exam AZ-500 and the Azure Security Engineer Associate certification on 31 August 2026, together with the renewal assessment. SC-500 became generally available on 21 July 2026 and is the replacement, with no conversion path and no upgrade exam. Most AZ-500 study still counts, because the identity, networking, storage, database and posture management content carried across, and the new material sits in securing artificial intelligence workloads. Anyone weighing up the change can read the full AZ-500 to SC-500 transition guide.

Training is instructor led and hands on, with mock questions and digital course material included, and the official certification exam fee is included in the course fee.

  • Microsoft’s current security engineer credential, replacing the retired Azure Security Engineer Associate certification
  • Proves you can secure identity, data, networking, compute and artificial intelligence workloads, the skills Australian employers are hiring for right now
  • Sits at associate level, above fundamentals and directly below the cybersecurity architect credential
  • Official certification exam fee included, no separate exam cost to budget for
  • Course material in digital format included, plus mock and test questions
  • Price beat guarantee on every course
  • Authorised test centre, so you can sit the exam at Logitrain, at any Pearson VUE test centre or online
  • Train in person in Melbourne, Sydney or Brisbane, or live online in real time with a trainer

There are no formal prerequisites, so you can enrol without holding another certification.

Microsoft assumes practical experience administering Azure and hybrid environments across compute, network and storage, strong familiarity with Microsoft Entra ID, and some familiarity with Microsoft 365 administration.

If you are still building that base, the AZ-104 Microsoft Azure Administrator course is the better starting point, and the AZ-900 Microsoft Azure Fundamentals course comes first again if Azure itself is new to you.

Candidates can achieve this certification by passing the following exam.

  • Exam SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, leading to the Microsoft Certified: Cloud and AI Security Engineer Associate certification

You can book and sit the exam within three months of finishing your course. Sit it at any Pearson VUE test centre, or online through Pearson VUE online proctoring from a private space.

Exam format: multiple choice and performance based questions, 120 minutes, with a passing score of 700 out of 1000. Microsoft does not publish a fixed question count for this exam.

SC-500 course material in digital format, mapped to the four skill areas Microsoft measures on the exam.

  • Implement and configure Privileged Identity Management in Microsoft Entra ID
  • Apply conditional access policies to protect cloud resources and agent identities
  • Configure authentication methods, including multifactor authentication and passwordless sign in
  • Manage app registrations, enterprise applications, OAuth permission grants and consent settings
  • Deploy and secure Azure Key Vault, and manage keys, secrets and certificates
  • Enforce governance and regulatory compliance using Azure Policy, resource locks and Defender for Cloud
  • Right size role assignments and remediate overprivileged access using Azure role based access control
  • Secure storage accounts with firewall rules, access policies and Defender for Storage
  • Secure Azure SQL Database and Azure SQL Managed Instance with auditing and platform level controls
  • Design and implement network security groups, application security groups and Azure Virtual Network Manager policies
  • Configure Azure Firewall, private endpoints, Private Link and Microsoft Entra Private Access
  • Secure servers and virtual machines with disk encryption, Azure Bastion, just in time access and Defender for Servers
  • Extend security controls to hybrid and multicloud servers using Azure Arc
  • Protect containers, Azure Kubernetes Service, Container Registry and Container Apps
  • Secure Azure App Service, Functions, Logic Apps and API Management, and configure Azure Web Application Firewall
  • Identify artificial intelligence risks using Microsoft Purview Data Security Posture Management
  • Configure real time protection for Copilot Studio agents and manage Microsoft Entra Agent ID access
  • Deploy AI Gateway in Azure API Management and configure guardrails in Microsoft Foundry
  • Manage security posture and workload protection plans in Microsoft Defender for Cloud
  • Connect data sources, build automation rules and manage data retention in Microsoft Sentinel
  • Configure workspaces, permissions, plugins and agents in Microsoft Security Copilot
  • Azure security engineers
  • Cloud security engineers
  • Azure administrators moving into security
  • Security operations analysts
  • Systems and infrastructure engineers
  • Identity and access administrators
  • DevOps engineers responsible for cloud security controls
  • Security consultants working in Microsoft environments
  • Holders of the retired Azure Security Engineer Associate certification updating to the current credential
  • IT professionals with hands on Azure experience moving into a cyber security role
  • Implement and configure Privileged Identity Management
  • Implement conditional access policies
  • Implement and configure authentication methods, including multifactor authentication and passwordless
  • Implement and configure identity for applications, including enterprise applications and app registrations
  • Manage OAuth permission grants and consent settings
  • Implement and configure managed identities for Azure resources
  • Deploy Azure Key Vault
  • Configure Key Vault settings
  • Configure access to Key Vault
  • Configure firewall settings on Key Vault
  • Manage keys, secrets and certificates
  • Scan for secrets using Defender Cloud Security Posture Management
  • Implement Defender for Key Vault
  • Implement and configure security controls using Azure Policy, including built in and custom policy definitions
  • Evaluate regulatory compliance using Microsoft Defender for Cloud
  • Implement and configure security controls in Defender for Cloud, including security standards and recommendations
  • Implement resource locks
  • Manage Azure built in role assignments
  • Manage custom roles, including Azure roles and Microsoft Entra roles
  • Evaluate and remediate overprivileged access assignments using Azure role based access control
  • Configure security controls for backup protection using Azure Backup security features
  • Implement and configure security controls using infrastructure as code
  • Implement and configure security for storage accounts
  • Configure Azure Storage firewall rules
  • Implement Defender for Storage threat protection configurations
  • Manage access to storage, including access policies
  • Implement platform level security configurations in Azure SQL
  • Configure database auditing for Azure SQL Database and Azure SQL Managed Instance
  • Configure Defender for Databases protection across Azure database services
  • Implement and manage network security groups and application security groups
  • Implement and configure network access policies using Azure Virtual Network Manager
  • Configure security for an Azure Virtual WAN
  • Implement and configure security for virtual private network connections
  • Implement and configure Microsoft Entra Private Access
  • Configure Azure private endpoints to secure access to platform as a service resources
  • Configure Azure Private Link services to secure access to network resources
  • Implement and configure Azure Firewall
  • Evaluate effective security rules using Azure Network Watcher diagnostics
  • Identify overexposure of data in SharePoint
  • Identify risks related to Microsoft Copilot and AI apps using Microsoft Purview Data Security Posture Management
  • Enable and configure real time protection for Microsoft Copilot Studio agents
  • Implement conditional access for Microsoft Entra Agent ID
  • Analyse blast radius for security risks related to Entra Agent ID using Defender XDR
  • Manage Entra Agent ID access
  • Configure and deploy AI Gateway in Azure API Management for Microsoft Foundry
  • Enable Defender for AI Service in Cloud Workload Protection in Defender for Cloud
  • Configure guardrails for agent security in Foundry
  • Monitor AI security using the data and AI security dashboard in Defender for Cloud
  • Manage agents in the Microsoft 365 admin centre
  • Implement and configure disk encryption
  • Plan and implement Azure Bastion
  • Enable and enforce use of just in time virtual machine access
  • Extend security controls to hybrid and multicloud servers using Azure Arc
  • Onboard servers to Defender for Servers, including hybrid and multicloud scenarios
  • Configure Defender for Servers settings, including vulnerability scanning and endpoint detection and response
  • Implement and manage agentless scanning for virtual machines in Defender for Servers
  • Configure virtual machine security features, including secure boot, virtual Trusted Platform Module, integrity monitoring and security type
  • Enforce security configuration of Azure managed servers using Azure Machine Configuration
  • Detect misconfigurations and runtime risks in container workloads using Defender for Containers
  • Implement and configure security controls for Azure Kubernetes Service
  • Implement and configure security controls for Azure Container Registry
  • Implement and configure security controls for Azure Container Instances and Azure Container Apps
  • Implement and configure security controls for Azure Functions, including authentication and network access
  • Implement and configure security controls for Azure Logic Apps
  • Implement and configure security controls for Azure App Service
  • Implement and configure Azure Web Application Firewall
  • Implement security policies for back end API protection using API Management
  • Identify security risks using Defender Cloud Security Posture Management
  • Evaluate compliance against security frameworks using Defender for Cloud
  • Enable and configure Defender for Cloud workload protection plans
  • Connect hybrid cloud and multicloud environments to Defender for Cloud, including Amazon Web Services and Google Cloud Platform
  • Configure Microsoft Defender Vulnerability Management settings for Azure virtual machines
  • Discover unprotected assets and vulnerabilities using Microsoft Defender External Attack Surface Management
  • Create and connect workspaces in Microsoft Sentinel
  • Assign roles in Microsoft Sentinel
  • Implement and use content hub solutions
  • Configure and use Microsoft data connectors for Azure resources
  • Implement and configure syslog and Common Event Format event collections
  • Implement and configure collection of Windows security events using data collection rules
  • Create custom log tables in the workspace to store ingested data
  • Implement automation rules and playbooks in Microsoft Sentinel
  • Implement data retention in Microsoft Sentinel data stores
  • Query Microsoft Purview Audit in Defender XDR
  • Configure workspaces for Microsoft Security Copilot
  • Manage permissions and roles in Security Copilot
  • Enable and configure plugins
  • Enable and configure Microsoft agents and Security Store agents

Got a team to train? Logitrain can deliver the SC-500 Cloud and AI Security Engineer course in house at your premises anywhere in Australia, course material, mock test and official exam fee as the public courses.

It suits teams who want everyone trained together on dates that suit the business. See in house training or call 1800 159 151.

Get our expert trainers at your premises. Logitrain Customised Team can tailor the course to meet your organisation's specific learning and development needs and business goals.
  • Date Format: DD dash MM dash YYYY
  • This field is for validation purposes and should be left unchanged.

What is the Microsoft Certified Cloud and AI Security Engineer Associate certification?

It is Microsoft’s associate level credential for security engineers who protect identities, storage, databases, networking, compute and artificial intelligence workloads across Azure, hybrid and multicloud environments.

Which certification does this replace?

It replaces the Microsoft Certified: Azure Security Engineer Associate certification, which Microsoft retired on 31 August 2026. If you hold the older credential, this is the current path to stay up to date.

Is the certification exam included in the course?

Yes. The official Microsoft certification exam fee is included, and you can book and sit the exam within three months of finishing your course.

What are the prerequisites?

There are no formal prerequisites. Microsoft assumes hands on experience administering Azure and hybrid environments, strong familiarity with Microsoft Entra ID and some familiarity with Microsoft 365 administration.

Which course should I do first?

If Azure is new to you, do AZ-900 and then AZ-104. If you already administer Azure day to day, come straight into this course.

How long is the course?

Four days full time on weekdays, or four weeks part time on weeknights or weekends.

Where can I do the training?

In person in Melbourne, Sydney, Brisbane, Adelaide, Perth and Canberra, plus live online across Australia, all delivered live in real time with a trainer.

Can I do the training online?

Yes. Live online training runs in real time with a trainer and the same course material, so you can join from anywhere in Australia.

How much AI content is in this course?

A full skill area covers securing artificial intelligence workloads, including Microsoft Copilot risk, Entra Agent ID, Microsoft Foundry guardrails and Defender for AI Services.

Where can I sit the exam?

At Logitrain as an authorised test centre, at any Pearson VUE test centre, or online through Pearson VUE online proctoring from a private space.

What jobs does this certification lead to?

Cloud security engineer, Azure security engineer, security consultant and security operations roles in Microsoft environments.

Request Information
  • five star ratings
    High-quality, cost-effective training since 2004
  • This field is for validation purposes and should be left unchanged.
What is included with the SC-500 Certification Training Course?
Logitrain course includes official certification exam fee.
Includes Official Exam Fee

Take the certification exam within 3 months of course / module completion

Logitrain is an Authorised Pearson VUE Test Centre.
Authorised Test Centre

Take the official certification exam at Logitrain, a local VUE test centre or online

Logitrain courses, programs and packages includes course material.
Includes Course Material

Course material in digital format is included for flexibility and ease of use

Logitrain courses, packages and programs includes sample practise questions.
Includes Mock & Test Questions

Mock test is included in the full-time courses to assist with your preparation

Skilled Trainers
Highly Skilled Trainers

Our trainers are highly skilled with expertise and extensive hands-on experience

Logitrain courses include price beat guarantee.
Our Price Beat Guarantee

Relax, we will beat competitor’s advertised price. Our course has no extra costs

Proposed Dates, Locations & Prices
Logitrain Live Online Training Banner

LocationTypeDurationPriceDates
LocationTypeDurationPriceDates

The supply of this course/package/program is governed by our terms and conditions. Please read them carefully before enrolling, as enrolment is conditional on acceptance of these terms and conditions. Proposed course dates are given, course runs subject to availability and minimum registrations.

OUR ACCREDITATIONS
Logitrain IT training accreditations and industry partnerships
Why Choose Logitrain
IT job ready in 8 weeks LogitrainPrepare to get IT job ready in 8 weeks

15000 IT professionals trained at LogitrainTrained 15,000+ professionals and counting

Logitrain IT training provider since 2004Experienced Provider: Operating Since 2004

IT training for Australian businesses LogitrainTrained staff from 2,500+ Australian Businesses

We Have Placed Candidates In
Logitrain has placed candidates in leading Australian Companies
SATISFIED CUSTOMERS

“Fantastic delivery! extremely knowledgeable trainer! great real-world experience with easy examples! convenient location!”
– Spiros L, Senior IT Officer at BOM, Rating: 5/5

“Everything was great, describing technologies in real world examples was fantastic. Logitrain has been a fresh surprise.”
– John D, ICT Manager at Glenvill, Rating: 5/5

“Thanks for a great week! Really enjoyed and feel I picked up a lot. Great Trainer! Will definitely look at further studies here.”
– Steven B, Senior Service Centre Analyst at News Corp Australia, Rating: 5/5

“The trainer was very patient and gave everybody the opportunity to participate. Gots lots of opportunity for hands-on practise”
– Tim S, Solutions Architect at MSC Mobility Solutions, Rating: 5/5

SOME OF OUR CLIENTS

Over 2,500 organisations have relied on Logitrain to be their trusted training partner.

Logitrain Clients
five star ratings
High-quality, cost-effective training since 2004
Learn More
  • This field is for validation purposes and should be left unchanged.
create

Don’t Wait. Please fill the form now.

  • Date Format: DD dash MM dash YYYY
  • This field is for validation purposes and should be left unchanged.

This will close in 20 seconds