As organizations accelerate their use of cloud platforms, AI tools, and Microsoft security technologies, the role of the security engineer is expanding. Security professionals are no longer focused only on protecting networks, endpoints, or individual systems. They are increasingly expected to understand identity, data, applications, infrastructure, compliance, AI workloads, and security posture as one connected environment.
That shift was the focus of a recent episode of The Security Insights Show, where Andre Keartland, Solutions Architect at Netsurit, joined Frank Grimberg and Edward Walton to discuss Microsoft’s new SC-500 exam, “Implementing End-to-End Security Controls for Cloud and AI Workloads.”
[Embed podcast video here – https://www.youtube.com/watch?v=4bhzsjGAXXE]
Keartland was invited to share his perspective on the exam after helping develop it for Microsoft Learning. The discussion moved beyond the structure of the exam itself and explored a broader question facing the Microsoft security community: what skills will security professionals need as cloud and AI become central to everyday business operations?
The answer is becoming clearer. Security teams need practical, end-to-end knowledge. They need to understand how modern Microsoft environments are built, how they are used, where risk is introduced, and how security controls should be implemented across the full technology stack.
TL;DR
- Microsoft’s SC-500 sets the new standard for end-to-end cloud and AI security across identity, data, infrastructure, and compliance
- AI adoption exposes existing security gaps — businesses need strong foundations before scaling AI tools responsibly
- The AZ-500 certification retires on 31 August 2026, making SC-500 the benchmark for Microsoft security engineers
- Businesses need partners and internal teams who understand Microsoft environments at a deeper level as cloud and AI investment grows
- Netsurit’s Andre Keartland contributed to developing the SC-500 exam, reflecting deep Microsoft security expertise within the company
A new exam for a changing security role
Microsoft’s SC-500 exam is aligned to the Microsoft Certified: Cloud and AI Security Engineer Associate certification. According to Microsoft Learn, the certification validates the ability to design, implement, and manage end-to-end security controls across Azure, hybrid, and AI-enabled environments.
That positioning is important. It reflects the fact that security is no longer a set of isolated controls applied after a technology decision has been made. In modern organizations, security needs to be part of the way cloud environments are configured, how identities are managed, how data is governed, how applications are protected, and how AI workloads are monitored.
Microsoft’s official SC-500 study guide outlines a security engineer role that spans identity, network, application, data, and compute. It also highlights the need to ensure that platforms, data, identities, and infrastructure used by AI workloads are securely implemented and monitored.
For organizations already invested in Microsoft technologies, this makes SC-500 particularly relevant. Many businesses are expanding their use of Azure, Microsoft 365, Microsoft Defender, Microsoft Entra ID, Microsoft Security Copilot, and AI-enabled workplace tools. As this environment grows, the security conversation has to mature with it.
The new certification is not only about testing product knowledge. It is about validating whether security professionals can apply that knowledge in complex, connected environments.
For more information on the certification, visit Microsoft Learn: https://learn.microsoft.com/en-us/credentials/certifications/cloud-and-ai-security-engineer-associate/
Why AI changes the security conversation
AI adoption has moved quickly from experimentation to implementation. Employees are using AI tools to summarize information, draft content, analyze data, automate tasks, and make faster decisions. Development teams are exploring AI-assisted coding and intelligent applications. Business leaders are looking at AI agents, workflow automation, and new ways to improve productivity.
This progress creates opportunity, but it also introduces security questions that cannot be ignored. What data is being used by AI tools? Who has access to that data? How are identities and permissions controlled? Are sensitive documents properly classified? Can AI workloads be monitored? Are cloud environments configured securely enough to support AI adoption? How will security teams detect misuse, overexposure, or risky behavior?
These questions are not theoretical. They are already part of day-to-day technology planning for many businesses. That is why the SC-500 exam’s focus on cloud and AI workloads is timely. AI security does not sit apart from cloud security, identity security, data security, or compliance. It depends on all of them. If the underlying environment is poorly governed, AI adoption can increase the speed and scale at which risk spreads through the business.
For businesses looking to strengthen their Microsoft security environment, Netsurit Secure helps organizations build stronger visibility, protection, response, and Microsoft 365 security posture.
Learn more here: https://netsurit.com/en-us/cybersecurity/
Certification as a career accelerator
One of the strongest themes in the podcast was the role of certification in a security career. In fast-changing technology fields, certification gives professionals a structured path for learning. It helps them understand what matters, where their knowledge gaps are, and how individual technologies fit together.
This is especially valuable in Microsoft security, where the ecosystem includes identity, endpoint protection, cloud infrastructure, compliance, threat detection, posture management, and now AI security.
However, the conversation also made clear that certification is not the finish line. Passing an exam demonstrates knowledge, but successful security professionals still need hands-on experience, judgement, curiosity, and the ability to apply what they have learned in real environments.
This is one of the reasons why SC-500 is significant. It is not narrowly focused on a single product or a single security function. It requires security professionals to think across domains. The skills measured include identity, access, governance, storage, databases, networking, compute, and security posture management.
For people building careers in Microsoft security, that creates a broader development path. It encourages professionals to connect technical implementation with business risk, user behavior, AI adoption, and operational resilience.
For employers, certifications like SC-500 can also help support hiring, development, and team planning. They create a shared benchmark for the skills security teams need as organizations invest more deeply in Microsoft cloud and AI technologies.
What this means for Microsoft-focused businesses
The SC-500 exam also sends a message to business leaders. As organizations move further into cloud and AI, they will need partners and internal teams who understand Microsoft environments at a deeper level.
It is no longer enough to deploy tools and assume the environment is secure. Businesses need to know whether their identities are properly protected, whether access is appropriately governed, whether cloud resources are configured securely, whether data is protected, and whether AI workloads can be monitored and managed.
This is particularly important for organizations adopting Microsoft 365 Copilot, Azure AI services, and AI-enabled applications. These tools can only deliver sustainable business value if the environment around them is secure, well governed, and aligned to business needs.
Netsurit’s Microsoft Solutions team works with businesses to plan, deploy, secure, and optimize Microsoft environments. Learn more here: https://netsurit.com/en-us/microsoft-solutions/
The same applies to Microsoft 365. Many organizations already rely on Microsoft 365 as a core productivity platform, but security depends on how it is configured, monitored, and supported. Netsurit’s Microsoft 365 services help businesses improve collaboration while keeping security built into the environment. Learn more here: https://netsurit.com/en-us/microsoft-365/
Practical skills matter more than ever
The Security Insights Show discussion highlighted a reality many security professionals already know: technology does not stand still. Cloud security skills that were sufficient a few years ago may not be enough for today’s AI-enabled environments. Security teams are being asked to support faster innovation, more complex systems, and more demanding compliance expectations.
That is why practical learning matters. The Microsoft Learn SC-500 course is designed to help security engineers build skills in identity security, cloud infrastructure protection, threat detection, and posture management across Microsoft environments.
For professionals preparing for the exam, the learning path is useful because it reflects real operational responsibilities. Security engineers are expected to work with architects, administrators, engineers, analysts, developers, and business stakeholders. Their role connects technical implementation with broader organizational risk.
For companies, this reinforces the importance of building or partnering for the right expertise. Security is not only a technology investment. It is a people and skills investment.
Netsurit expertise in the Microsoft security community
Keartland’s involvement in the development of the SC-500 exam reflects the depth of Microsoft security expertise within Netsurit. It also demonstrates the company’s connection to the broader Microsoft security community, where practical experience and continuous learning are essential.
The podcast appearance is a strong reminder that cybersecurity leadership is not only about responding to threats. It is also about helping shape how the industry learns, prepares, and develops the next generation of security professionals.
For Netsurit customers, this expertise matters because security decisions are becoming more complex. Businesses need guidance that is rooted in real Microsoft experience, practical implementation, and an understanding of how cloud and AI are changing the risk landscape.
Explore Netsurit’s broader services here: https://netsurit.com/en-us/our-services/
FAQs
Q: What is the Microsoft SC-500 certification? A: SC-500, or Microsoft Certified: Cloud and AI Security Engineer Associate, validates the ability to design and manage end-to-end security controls across Azure, hybrid, and AI-enabled environments. It covers identity, data, network, compute, and AI security posture management.
Q: Why does SC-500 matter for businesses using Microsoft technologies? A: As organizations expand their use of Azure, Microsoft 365, and AI tools, security needs to mature with the environment. SC-500 validates whether security professionals can apply end-to-end controls across cloud and AI workloads, not just individual tools or products.
Q: How does AI adoption change security requirements? A: AI tools depend on access, permissions, and data. If the underlying environment is poorly governed, AI adoption can increase the speed and scale at which risk spreads. Security must cover identity, data classification, cloud configuration, and monitoring before AI can be scaled safely.
Q: What happens to the AZ-500 certification? A: Microsoft has confirmed the Azure Security Engineer Associate certification and AZ-500 exam are retiring on 31 August 2026. SC-500 replaces it as the standard for cloud and AI security engineering.
Q: What is Netsurit’s connection to the SC-500 exam? A: Andre Keartland, Solutions Architect at Netsurit, contributed to developing the SC-500 exam for Microsoft Learning, reflecting the company’s practical depth in Microsoft security across cloud and AI environments.
Q: How can businesses build the right Microsoft security expertise? A: Businesses can build internal capability, partner with a Microsoft Solutions Partner, or combine both. The priority is ensuring cloud environments are correctly configured, identities are governed, and AI workloads are monitored before scaling adoption further.
