Azure Fundamentals Certification Guide
·10 min read
Everything the AZ-900 exam covers — domains, format, cost and passing score — plus a study plan and practice-test strategy for Azure Fundamentals.
Continue readingA decision framework for choosing between Azure's security engineer credential and vendor-neutral certifications like CompTIA Security+ and CISSP.

"Should I take AZ-500 or a vendor-neutral security certification?" is really two questions wearing one coat. The first — vendor-specific versus vendor-neutral — is a durable career-strategy question. The second — should AZ-500 specifically be your Azure security credential — has been overtaken by events: Microsoft's official Learn page states that the Azure Security Engineer Associate certification, its exam and its renewal assessments retire on 31 August 2026, after which it can no longer be earned or renewed. Secondary sources name a successor exam, SC-500, for a Cloud and AI Security Engineer Associate credential, though official details were not published at the time of writing.
So the honest framing for late 2026 is: how should a Microsoft-platform security credential — whatever Microsoft's current one is called — sit alongside vendor-neutral certifications such as CompTIA Security+ and ISC2's Certified Information Systems Security Professional (CISSP)? That decision framework is what this article provides. It is not an AZ-500 exam walkthrough; for the exam's domains and history, see the AZ-500 exam guide.
Every certification is a claim you make to an employer, and the two families make different claims.
A vendor certification like Azure Security Engineer Associate claims: I can operate this specific platform's security controls. While it was live, AZ-500 tested securing identity and access, securing networking, securing compute, storage and databases, and running security operations with Microsoft Defender for Cloud and Microsoft Sentinel. That is implementation-level knowledge: portals, policies, product capabilities. It is worth the most to an employer whose estate runs on that platform, and it depreciates when the platform changes — as the 2026 retirement wave demonstrates rather pointedly.
A vendor-neutral certification claims: I understand security itself. CompTIA Security+ is positioned as a broad, foundational credential covering security concepts across any environment; CISSP is positioned as a senior credential in security architecture, governance and management, with substantial professional-experience requirements set by ISC2. (Their exam formats, fees and experience rules change over time — confirm current details on comptia.org and isc2.org rather than on any blog, this one included.) These credentials transfer across employers and platforms, and they age more slowly, because the concepts they test — least privilege, defence in depth, risk management — outlive any product.
Neither claim is "better". They answer different interview questions: "can you secure our Azure tenant on Monday?" versus "do you understand security well enough to be trusted with it anywhere?"
| Factor | Azure Security Engineer (AZ-500 track) | CompTIA Security+ | CISSP |
|---|---|---|---|
| Type | Vendor (Microsoft Azure) | Vendor-neutral, foundational | Vendor-neutral, senior |
| Scope | Implementing security on one cloud platform | Broad security fundamentals across environments | Security architecture, governance and management |
| Prerequisites | None formal (Microsoft associate certs have no mandatory prereqs) | None formal — check CompTIA's current recommendations | Substantial verified professional experience — check ISC2's current rules |
| Status 2026 | Retires 31 Aug 2026; successor exam SC-500 named by secondary sources | Active — confirm current version on comptia.org | Active — confirm current requirements on isc2.org |
| Cost | Priced per country/region by Microsoft — confirm on the exam page | See comptia.org for current pricing | See isc2.org for current pricing |
| Renewal | Microsoft role-based certs: 1 year, renewed free via an online open-book assessment | Follows CompTIA's continuing-education programme — see comptia.org | Follows ISC2's continuing-education programme — see isc2.org |
| Strongest signal to | Employers running Microsoft/Azure estates | Employers hiring early-career security staff; roles with baseline-cert requirements | Employers hiring security leadership and architecture |
| Weakness | Depreciates with platform change; means less in non-Microsoft shops | Breadth without platform depth | Experience gate puts it out of early-career reach |
Where the table says "confirm on the official page", that is deliberate: pricing, formats and policies for the CompTIA and ISC2 exams were outside the scope of what we could verify for this article, and quoting stale figures would serve you worse than a pointer to the source.
If you have little or no security work history, a vendor-neutral foundation usually earns its place first: it gives recruiters a recognised baseline signal, and many role descriptions (including in regulated and government-adjacent environments) explicitly ask for one. A platform security credential lands better once there is a platform in your life to secure. If you are so early that even cloud basics are new, note that Microsoft's fundamentals tier — including Security, Compliance, and Identity Fundamentals (SC-900) — has no prerequisites, never expires, and is a gentler on-ramp than any of the certs above.
This is the single most predictive question. A security engineer at a Microsoft-committed organisation lives in Entra ID, Defender and Sentinel all day; the vendor credential maps directly onto the job, and hiring managers there read it as immediately useful. In a multi-cloud or non-Microsoft shop, the same credential reads as "adjacent experience" at best. Vendor-neutral certs never suffer that discount, but they also never earn the "can start on our stack tomorrow" premium.
The 2026 Microsoft overhaul is a live lesson: AZ-500 holders keep the credential on their transcripts, but once it lapses it cannot be renewed, and new candidates must wait for the successor. Vendor certifications track products, so they refresh and retire on the vendor's schedule; Microsoft softens this with free annual online renewal while a cert is current, but retirement is retirement. Concept-based certifications move slower. If you change employers or platforms often, weight your portfolio towards vendor-neutral; if you are settled in a Microsoft ecosystem, the platform credential's shorter half-life is a fair trade for its relevance.
Platform security certifications are practitioner credentials: they say you can configure, monitor and respond. CISSP-style credentials increasingly matter at the level where you design programmes, own risk and manage teams. A common and sensible long arc is platform-practitioner credentials in the first half of a security career and a senior vendor-neutral credential once the experience requirements are within reach.
A realistic composite: an infrastructure engineer at a company mid-migration to Azure wants to pivot into security. A defensible three-step plan is a vendor-neutral foundation (Security+ or equivalent) to establish the baseline vocabulary and pass HR filters; then Microsoft's platform security credentials — SC-900 as a low-cost starting point, then whichever associate-level security certification Microsoft offers when they are ready, alongside active certs like Security Operations Analyst (SC-200), which remains available and Sentinel-centred; and eventually a senior vendor-neutral credential once the experience accrues. The pairing works because each certificate covers the other's weakness: the neutral cert proves the concepts travel, the vendor cert proves you can execute on the estate you are actually paid to defend.
What that plan never includes is sitting AZ-500 now — the window has effectively closed. Anyone whose study plan still says "AZ-500" should check the official Microsoft Learn security engineer page for the current credential before spending a further hour on preparation.
The study mechanics differ more than people expect. Platform exams reward hands-on time in a tenant; concept exams reward breadth and terminology. In both cases, timed practice questions are the cheapest way to find weak domains before the exam does — ExamPractice's Microsoft exams hub carries free sample questions for the Microsoft security track (including the AZ-500 question archive and SC-900 practice questions), with fuller sets and timed simulation for subscribers. Use results diagnostically — retest the domains you miss, not the questions.
No — Microsoft's official page states the certification and exam retire on 31 August 2026, so it is no longer a viable target. Watch Microsoft Learn for the successor security engineer credential (secondary sources name exam SC-500), or consider active Microsoft security certs such as SC-200.
Role-based certifications like the security associate tier expire after one year but renew free through an unproctored, open-book online assessment on Microsoft Learn, retakeable without limit in the six months before expiry. Fundamentals certifications such as SC-900 never expire.
You can, and some Azure-house engineers do. The trade-off appears when you change jobs: vendor-neutral credentials are the ones that survive a move to a different stack, so an Azure-only portfolio concentrates career risk on one vendor's ecosystem and retirement schedule.
They are hard in different ways — one tests platform implementation depth, the other tests broad senior-level judgement with an experience gate — and difficulty comparisons across providers are subjective. Judge each against its own official objectives rather than against the other.
Choose by circumstance, not by tribe. Early-career and platform-uncommitted: vendor-neutral foundation first. Employed in a Microsoft estate: platform security credentials pay off fastest — just aim at the currently active ones, not the retiring AZ-500. Senior trajectory: plan for a vendor-neutral capstone. And whatever the shortlist, verify formats, fees and dates on the provider's own page the week you book, because if 2026 has proven anything about security certifications, it is that the map changes under your feet.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·10 min read
Everything the AZ-900 exam covers — domains, format, cost and passing score — plus a study plan and practice-test strategy for Azure Fundamentals.
Continue reading·10 min read
A full AZ-104 exam guide for IT admins — the five domains, hands-on skills Microsoft expects, format, cost, renewal and a prep strategy that works.
Continue reading·10 min read
The AZ-204 Azure Developer Associate certification is retired. What it covered, what happens to existing holders, and the current path for Azure developers.
Continue reading