SC-500 study plan: pass in 6 weeks
Six weeks rather than four, because SC-500 is wide and its domains are evenly weighted. There is no dominant area to prioritise and no small area to skip — every domain is worth roughly a quarter of the score. This plan assumes 8–10 hours a week and existing Azure administration experience.
Held AZ-500? Skip to the compressed plan at the bottom.
Week 1: identity, access and governance (20–25%)
- Entra ID: PIM, conditional access, MFA and passwordless, enterprise applications and app registrations, OAuth permission grants and consent settings, managed identities.
- Key Vault: deploy it, configure access and firewall settings, manage keys, secrets and certificates, scan for secrets with Defender CSPM, enable Defender for Key Vault.
Week 2: governance
Still domain one, but it deserves its own week — it is the part experienced engineers most often assume they know.
- Azure Policy, built-in and custom definitions.
- Regulatory compliance evaluation in Defender for Cloud; security standards and recommendations.
- Resource locks, built-in role assignments, custom Azure and Entra roles.
- Finding and remediating overprivileged access with RBAC.
- Azure Backup security features.
- Security controls through infrastructure as code.
Week 3: storage, databases and networking (25–30%)
The largest domain, and the most hands-on.
- Storage: account security, firewall rules, Defender for Storage, access policies.
- Databases: Azure SQL platform-level configuration, auditing for SQL Database and Managed Instance, Defender for Databases.
- Networking: NSGs and ASGs, Azure Virtual Network Manager, Virtual WAN, VPN, Entra Private Access, private endpoints, Private Link, Azure Firewall, and evaluating effective rules with Network Watcher.
Week 4: securing AI
Technically part of secure compute, but new enough to earn a week of its own. This is the material no AZ-500 resource covers.
- Data overexposure in SharePoint, and Purview DSPM for Copilot and AI app risks.
- Real-time protection for Copilot Studio agents.
- Entra Agent ID: conditional access for it, managing its access, and blast radius analysis in Defender XDR.
- AI Gateway in Azure API Management for Foundry.
- Defender for AI Services in Cloud Workload Protection.
- Guardrails for agent security in Foundry.
- The Data and AI security dashboard in Defender for Cloud.
- Managing agents in the Microsoft 365 admin center.
Week 5: the rest of compute (20–25%)
- Servers and VMs: disk encryption, Bastion, JIT VM access, Azure Arc for hybrid and multicloud, Defender for Servers including vulnerability scanning, EDR and agentless scanning, VM security features (secure boot, vTPM, integrity monitoring, security type), and Azure Machine Configuration.
- Application platform: Defender for Containers, AKS, Container Registry, Container Instances and Container Apps, Functions, Logic Apps, App Service, Web Application Firewall, and back-end API protection with API Management.
Week 6: posture, monitoring and revision (20–25%)
- Defender for Cloud: CSPM, compliance against frameworks, workload protection plans, connecting AWS and GCP, Defender Vulnerability Management, and EASM.
- Sentinel: workspaces, roles, content hub, data connectors, syslog and CEF, Windows Security events via data collection rules and WEF, custom log tables, automation rules and playbooks, retention, and querying Purview Audit in Defender XDR.
- Security Copilot: workspaces, permissions and roles, plugins, and Microsoft and Security Store agents.
- Then a full practice exam under real conditions, mistakes sorted by domain, weakest domain rebuilt, second practice exam.
Where the hours go
| Week | Focus | Hours |
|---|---|---|
| 1 | Entra ID and Key Vault | 8–10 |
| 2 | Governance and compliance | 8–10 |
| 3 | Storage, databases, networking | 8–10 |
| 4 | Securing AI | 8–10 |
| 5 | Servers, VMs, containers, app platform | 8–10 |
| 6 | Posture, Sentinel, Security Copilot, revision | 8–10 |
Compressed plan for AZ-500 holders
Two to three weeks:
- Week 1: the whole of week 4 above — the AI objectives, start to finish.
- Week 2: Security Copilot, Entra Private Access, Virtual Network Manager, EASM, and the container objectives.
- Week 3 (optional): a practice exam, then light revision of whatever the score report flags.
Everything else you already know. Do not re-study Entra ID and Key Vault from scratch — verify with practice questions and move on.
Because the weighting is flat, coverage beats depth. Getting adequately through all four domains passes this exam; mastering two does not.