Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Microsoft
Exam Format
120 min
40-60
700
Associate
Registration
$165 USD
Pearson VUE, Certiport, or online proctoring
Validity
1 year
Free online renewal assessment on Microsoft Learn; Transition to one of the replacement certifications (SC-200, SC-300, or SC-400)
Exam Guide
MS-500 Exam Topics and Domains
MS-500 is organized into 4 weighted domains. Expect to work with Azure AD Connect, Microsoft Intune, ADFS, Authenticator app, and more.
1
Implement and manage identity and access
25%
Plan and implement identity and access for Microsoft 365 hybrid environments
Authentication methodsAzure AD synchronization
- Choose an authentication method to connect to a hybrid environment
- Plan and implement pass-through authentication and password hash sync
- Plan and implement Microsoft Entra synchronization for hybrid environments
- Monitor and troubleshoot Microsoft Entra Connect events
Plan and implement identities in Microsoft Entra ID
Group managementPassword managementExternal identities
- Implement Azure AD group membership
- Implement password management, including self-service password reset and Microsoft Entra Password Protection
- Manage external identities in Microsoft Entra ID and Microsoft 365 workloads
- Plan and implement roles and role groups
- Audit Microsoft Entra ID
Implement authentication methods
Multi-factor authenticationPasswordless authentication
- Implement multi-factor authentication (MFA) by using conditional access policies
- Manage and monitor MFA
- Plan and implement Windows Hello for Business, FIDO, and passwordless authentication
Plan and implement conditional access
Conditional access policiesDevice compliance
- Plan and implement conditional access policies
- Plan and implement device compliance policies
- Test and troubleshoot conditional access policies
Configure and manage identity governance
Privileged Identity ManagementEntitlement management
- Implement Microsoft Entra Privileged Identity Management
- Implement and manage entitlement management
- Implement and manage access reviews
Implement Microsoft Entra ID Protection
Risk policies
- Implement user risk policy
- Implement sign-in risk policy
- Configure Identity Protection alerts
- Review and respond to risk events
2
Implement and manage threat protection
30%
Secure identity by using Microsoft Defender for Identity
Defender for Identity deployment
- Plan a Microsoft Defender for Identity solution
- Install and configure Microsoft Defender for Identity
- Manage and monitor Microsoft Defender for Identity
- Analyze identity-related threats and risks identified in Microsoft 365 Defender
Secure endpoints by using Microsoft Defender for Endpoint
Endpoint protection deployment
- Plan a Microsoft Defender for Endpoint solution
- Implement Microsoft Defender for Endpoint
- Manage and monitor Microsoft Defender for Endpoint
- Analyze and remediate threats and risks to endpoints
Secure endpoints by using Microsoft Endpoint Manager
Application protection
- Plan for device and application protection
- Configure and manage Microsoft Defender Application Guard
- Configure and manage Windows Defender Application Control
- Configure and manage exploit protection
- Configure and manage device encryption
- Configure and manage application protection policies
Secure collaboration by using Microsoft Defender for Office 365
Email and collaboration protection
- Plan a Microsoft Defender for Office 365 solution
- Configure Microsoft Defender for Office 365
- Monitor for threats by using Microsoft Defender for Office 365
- Analyze and remediate threats and risks to collaboration workloads
- Conduct simulated attacks by using Attack simulation training
Detect and respond to threats using Microsoft Sentinel
SIEM and SOAR capabilities
- Plan a Microsoft Sentinel solution for Microsoft 365
- Implement and configure Microsoft Sentinel for Microsoft 365
- Manage and monitor Microsoft 365 security by using Microsoft Sentinel
- Respond to threats using built-in playbooks in Microsoft Sentinel
Secure connections to cloud apps
Cloud app security
- Plan Microsoft Defender for Cloud Apps implementation
- Configure Microsoft Defender for Cloud Apps
- Manage cloud app discovery
- Manage entries in the Microsoft Defender for Cloud Apps catalog
- Manage apps in Microsoft Defender for Cloud Apps
- Configure Microsoft Defender for Cloud Apps connectors and OAuth apps
- Configure Microsoft Defender for Cloud Apps policies and templates
- Manage App governance in Microsoft Defender for Cloud Apps
3
Implement and manage information protection
15%
Manage sensitive information
Sensitivity labelsSensitive information types
- Plan a sensitivity label solution
- Create and manage sensitive information types
- Configure sensitivity labels and policies
- Publish sensitivity labels to Microsoft 365 workloads
- Monitor data classification and label usage
Implement and manage Data Loss Prevention
DLP policiesEndpoint DLP
- Plan a DLP solution
- Create and manage DLP policies for Microsoft 365 workloads
- Implement and manage Endpoint DLP
- Monitor DLP
- Respond to DLP alerts and notifications
Plan and implement Data lifecycle management
Retention policies
- Plan for data lifecycle management
- Review and interpret data lifecycle management reports and dashboards
- Configure retention labels, policies, and label policies
- Plan and implement adaptive scopes
- Configure retention in Microsoft 365 workloads
- Find and recover deleted Office 365 data
4
Manage compliance in Microsoft 365
20%
Manage and analyze audit logs and reports
Audit logging
- Plan for auditing and reporting
- Investigate compliance activities by using audit logs
- Review and interpret compliance reports and dashboards
- Configure alert policies
- Configure audit retention policies
Plan for, conduct, and manage eDiscovery cases
eDiscovery
- Recommend eDiscovery Standard or Premium
- Plan for content search and eDiscovery
- Delegate permissions to use search and discovery tools
- Use search and investigation tools to discover and respond
- Manage eDiscovery cases
Manage regulatory and privacy requirements
Compliance management
- Plan for regulatory compliance in Microsoft 365
- Manage regulatory compliance in the Microsoft Purview Compliance Manager
- Implement privacy risk management in Microsoft Priva
- Implement and manage Subject Rights Requests in Microsoft Priva
Manage insider risk solutions
Insider risk managementCommunication complianceInformation barriers
- Implement and manage Customer Lockbox
- Implement and manage Communication compliance policies
- Implement and manage Insider risk management policies
- Implement and manage Information barrier policies
- Implement and manage Privileged access management
How do I earn this certification?
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
The most effective way to prepare for MS-500 is by using the PlanetCert Simulator to practice questions and review detailed explanations.
What's changed on this exam?
Current Status
- RETIRED
- Last content update: 2022-11-04
- Announcement date: 2023-03-01
Updates
- Microsoft Defender XDR Unified platform Replaces individual Defender products in new exams • Release date: 2024-01-01
- Microsoft Sentinel Enhanced with AI Greater focus on SIEM/SOAR in SC-200 • Release date: 2024-06-01
- Microsoft Entra ID Protection 2024 updates Core component of SC-300 • Release date: 2024-03-01
Who should take this exam?
- Functional experience with Microsoft 365 workloads
- Experience with Microsoft Entra ID
- Experience implementing security for Microsoft 365 environments
- Working knowledge of Windows clients and servers
- Understanding of Active Directory and PowerShell