Back to blog
Exam Guides10 min read

SC-500 Case Study Walkthrough (2026): How to Work Through a Cloud and AI Security Scenario

A worked SC-500 case study built from Microsoft's official skills outline: one fictional company, five security requirements, and the reasoning that separates the right control from the tempting one, including the AI agent traps.

Tom Ashford

Tom Ashford · Security Certifications Lead

27 September 2026

SC-500 Case Study Walkthrough (2026): How to Work Through a Cloud and AI Security Scenario

An SC-500 case study gives you a fictional company, a description of its environment and a list of requirements, then asks several questions against that one scenario. Microsoft does not say in advance which question types any exam uses, so nobody outside Microsoft can promise you a case study on your SC-500 sitting. Case studies are a standard part of Microsoft's role-based exams, though, and they are where scenario reasoning gets tested hardest. You should prepare for one.

This walkthrough builds a single scenario from the official SC-500 skills outline and works through it one requirement at a time. It is not a question bank. The aim is to show how the reasoning goes: which word in a requirement decides the answer, and where the obvious control is wrong.

How case studies work on Microsoft exams, SC-500 included

Microsoft publishes the mechanics in its exam FAQ and exam experience pages. The rules that change how you work:

  • You can refer back to the scenario as often as you like while you answer that case study's questions.
  • Once you leave a case study, you cannot return to it. You get a review screen at the end of each case, and that is your last chance to change those answers.
  • Case studies are not timed separately. They come out of the same exam clock as everything else. The introduction screen tells you how many case studies, labs and questions you have. Read it.
  • Taking a break locks what you have seen. If you start a break during a case study, you cannot return to any question you viewed before it.
  • Microsoft Learn is available during role-based exams, in a split screen. The timer keeps running while you use it, so it suits checking one setting, not studying a topic from scratch.

The published SC-500 facts that matter here: a score of 700 or greater is required to pass, and associate exams that may contain labs run for 120 minutes. Microsoft does not publish a question count or the number of case studies for SC-500. Any site quoting either is guessing.

Exam Tip: Try the free exam sandbox at aka.ms/examdemo before exam day. It uses the real exam interface, including the case study layout, so the navigation will not cost you time on the day.

The SC-500 case study scenario: Harrowgate Freight

Harrowgate Freight is a fictional company. The layout below follows the way Microsoft case studies are usually organised: overview, existing environment, then requirements.

Overview

Harrowgate Freight is a logistics company with 2,400 staff. It runs its customer platform in Azure and uses Microsoft 365 across the business. Two AI projects went live this year, and the security team is under pressure to control them without slowing either down.

Existing environment

  • A Microsoft Foundry resource hosts two projects: Dispatch, which answers customer delivery queries, and Pricing, which drafts freight quotes for the sales team.
  • Quote Assistant is an agent that sales staff sign in to. It reads their mailbox and CRM records to draft quotes.
  • Night Audit is an autonomous agent with its own identity. It runs at 02:00, reconciles invoices and emails a report. No user is signed in when it runs.
  • Night Audit pulls rates from a supplier API that authenticates with an API key.
  • The security team uses Microsoft Defender XDR, and Defender for Cloud is enabled on the production subscription with the servers and storage plans only.

Requirements

  1. Staff using Quote Assistant must complete multifactor authentication before the agent can read their mailbox.
  2. If Microsoft Entra ID Protection flags Night Audit as high risk, its access to company resources must stop automatically.
  3. The Dispatch project must not be able to consume the token capacity the Pricing project needs.
  4. The SOC must get alerts for jailbreak attempts against both projects, including the part of the prompt that triggered the alert.
  5. All access by Night Audit must be subject to Conditional Access.
  6. Solutions must minimise administrative effort.

That last line matters more than it looks. When a requirement says "minimise administrative effort", Microsoft wants the built-in, managed option, not a custom build that also works.

Working through the SC-500 case study, requirement by requirement

Requirement 1: MFA before Quote Assistant reads a mailbox

The tempting answer is a Conditional Access policy that targets the Quote Assistant agent identity and requires MFA. It is wrong, and the reason is how the token is issued.

Quote Assistant acts on behalf of a signed-in user, using the on-behalf-of flow. The user is the subject of the token, so Microsoft's guidance is that Conditional Access policies for this pattern target users and groups, not agent identities. The right answer is a policy on the sales users, targeting the resources the agent reaches (Exchange Online and the CRM app), requiring an MFA authentication strength.

An agent cannot complete MFA anyway. Any answer that asks an agent identity to satisfy an interactive control should make you suspicious.

Requirement 2: stop Night Audit automatically when it is high risk

Night Audit works in the opposite pattern. It uses its own identity with no user present, so here the policy does target the agent identity. The condition is agent risk from ID Protection, set to high.

The access control is where people slip. For an agent accessing resources with its own identity, blocking access is the only control available, because there is nothing to remediate interactively. If an answer option offers "require password change" or "require MFA" for this agent, eliminate it.

Requirement 3: stop Dispatch from starving Pricing

This one sits in the AI security section of the outline: configure and deploy AI Gateway in Azure API Management for Microsoft Foundry. AI Gateway puts API Management between clients and the model deployments, and its token limits apply at the project level. That maps exactly onto Dispatch and Pricing being separate projects.

You set a tokens-per-minute limit, a token quota, or both, on the Dispatch project. A request over the TPM limit returns 429 Too Many Requests, and a request over the total quota returns 403 Forbidden. A distractor might offer a lower TPM limit on the model deployment itself. That caps everyone sharing the deployment, including Pricing, so it misses the requirement.

Requirement 4: jailbreak alerts with the triggering prompt

The environment note says Defender for Cloud covers servers and storage only. That is the clue. Jailbreak alerts for AI workloads come from Defender for AI Services, the AI threat protection plan in Defender for Cloud, which works with Azure AI Content Safety Prompt Shields and forwards its alerts to Defender XDR.

The second half of the requirement needs a setting inside the plan. Suspicious prompt evidence is a separate toggle. With it off, Defender still analyses the prompts, but the prompt content is masked in the alert. The full answer is to enable the plan and turn on prompt evidence. Enabling threat detection at subscription level needs the Owner role at subscription scope, or specific roles with the corresponding data actions, which is often the "which role do you need" question attached to this scenario.

Exam Tip: Microsoft's alert reference separates a jailbreak attempt that Prompt Shields blocked from one it only detected. If a scenario says attempts are being logged but not stopped, look at the content filtering configuration, not the Defender plan.

Requirement 5: all Night Audit access under Conditional Access

This is the trap the scenario is built around. Night Audit calls the supplier API with an API key. Microsoft's documentation states that Conditional Access only protects resources secured by Microsoft Entra ID. An API key skips the Entra token process entirely, so no Conditional Access policy can apply to that call, however it is written.

You cannot meet requirement 5 with a policy change. The fix is to move that integration to Entra ID authentication, for example by fronting the supplier API with an Entra-protected endpoint, so that Night Audit requests a token that Conditional Access can evaluate. Case studies often put one requirement like this in the list, where the architecture has to change before any setting can work. Candidates who look for a checkbox lose the mark.

Where each requirement sits in the SC-500 skills outline

Mapping the scenario back to the official outline shows how much one case study can cover, and why the AI content is harder to avoid than its share of the weightings suggests.

RequirementControl that satisfies itSkills outline areaDomain weighting
1. MFA before mailbox accessConditional Access on users, MFA strengthManage identity, access, and governance20 to 25%
2. Block high-risk autonomous agentConditional Access for Entra Agent ID, agent risk, blockSecure compute (Implement security for AI)20 to 25%
3. Contain token use per projectAI Gateway token limit on the Foundry projectSecure compute (Implement security for AI)20 to 25%
4. Jailbreak alerts with evidenceDefender for AI Services plus prompt evidenceSecure compute (Implement security for AI)20 to 25%
5. Conditional Access on every callReplace API key with Entra authenticationManage identity, access, and governance20 to 25%

AI security has no domain of its own. Microsoft places it inside Secure compute, alongside VMs and application platform services. Our SC-500 exam topics and domain weightings guide breaks down how much of that domain the AI bullets account for.

A method for any SC-500 case study

The scenario changes on the day. The method does not.

  1. Read the requirements before the environment. The requirements tell you what to look for. Reading the environment first means reading it twice.
  2. Mark the qualifiers. "Minimise administrative effort", "least privilege", "without user interaction" and "automatically" each rule out answer options on their own.
  3. Find the token subject for every identity question. A user signed in means target users. An agent working alone means target the agent, and blocking is the only control.
  4. Check the environment for what is not enabled. Missing Defender plans, API keys and disabled toggles are placed there on purpose.
  5. Use the review screen before you leave. It is the last time you will see those answers.

For how to build the hands-on experience these questions assume, the 8-week SC-500 study plan spends a full week on the AI security content. If you are still deciding whether you are ready to book, Is SC-500 difficult? has a readiness check, and AZ-500 vs SC-500 covers what changed when AZ-500 retired.

Frequently Asked Questions

Does SC-500 have case studies?

Microsoft does not publish the question types for any individual exam, so it has not confirmed case studies for SC-500 specifically. Case studies are a standard format across Microsoft's role-based exams, and the exam introduction screen tells you how many your sitting contains. Prepare as though at least one will appear.

Can you go back to a case study on a Microsoft exam?

You can move freely between the questions in a case study and reread the scenario as often as you like. Once you leave the case study, you cannot return to it. Use the review screen at the end of each case to check your answers before moving on.

Can you use Microsoft Learn during the SC-500 exam?

Yes. Microsoft gives access to Microsoft Learn during role-based exams, in a split screen next to the question. No extra time is added and the exam timer keeps running, so use it to confirm a single detail rather than to research a topic.

What score do you need to pass SC-500?

A score of 700 or greater is required to pass, on Microsoft's scaled scoring. Microsoft does not publish how many questions you need to answer correctly to reach 700, because the scale is not a simple percentage.

Ready to Start Practising?

Reading a worked scenario is useful. Answering unseen ones under time pressure is what builds exam speed. The CertCrush SC-500 course covers all four domains with explained answers, including the Entra Agent ID, AI Gateway and Defender for AI Services content that most older material skips.

Create your free CertCrush account and start practising today.

SC-500MicrosoftCase StudyCloud and AI Security EngineerEntra Agent IDDefender for CloudExam Technique
Tom Ashford

Written by

Tom Ashford · Security Certifications Lead

Tom spent over a decade in security operations and consulting before turning to full-time exam-prep writing. He covers the big security certifications — CISSP, CISM, CISA, Security+ and the rest of the alphabet — with a soft spot for the questions everyone gets wrong. His rule for every article: if it doesn’t help you score marks, it doesn’t go in.

All articles by Tom

Practise for Microsoft SC-500 — free

10 real exam-style questions with full explanations, no account needed. Then unlock the complete bank with an exam-readiness score and a daily plan built around your exam date.