Week 1— Manage identity and access · Secure networking
7 days- Study →
Manage identity and access
Manage identity and access is roughly 9% of AZ-500 and concentrates on Microsoft Entra ID: users, groups, and external identities; authentication methods including MFA and passwordless; conditional access policies; and privileged identity management. Expect scenario questions where you choose the least-privilege configuration, diagnose why a sign-in or policy failed, and map governance controls such as access reviews and PIM role assignments to a stated requirement.
📅 Days 4–6🎯 ~62 questions/day⚖ 9% of exam- ✓Create and manage Entra ID users, groups, and dynamic membership rules
- ✓Configure authentication methods: MFA, passwordless FIDO2, and SSPR registration
- ✓Build Conditional Access policies with sign-in risk and device conditions
- Study →
Secure networking
Secure networking is 24% of AZ-500 and covers designing and configuring network controls that protect Azure workloads. Expect scenario items on NSG and Azure Firewall rules, service endpoints versus private endpoints, VNet peering and routing, DDoS Protection, and Bastion or VPN access, plus interpreting effective security rules and diagnosing connectivity failures.
📅 Days 4–7🎯 ~10 questions/day⚖ 24% of exam- ✓Configuring NSG security rules, priorities, and application security groups for subnet traffic
- ✓Choosing Azure Firewall, NSG, or WAF for filtering and inspecting network flows
- ✓Implementing Private Link and private endpoints versus service endpoints for PaaS access