Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard
A large enterprise has hundreds of Azure subscriptions across various departments. They need to apply a consistent set of Azure Policies and Role-Based Access Control (RBAC) assignments uniformly across multiple subscriptions to ensure governance and compliance. Which Azure organizational construct is specifically designed to manage access, policy, and compliance for multiple subscriptions at scale?
- AAzure Blueprints
- BAzure AD Tenants
- CAzure Resource Groups
- DAzure Management Groups
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Management Groups
Azure Management Groups provide a level of scope above subscriptions. You can organize subscriptions into management groups, and apply your governance conditions (like policies and RBAC assignments) at the management group level. All subscriptions within that management group automatically inherit these conditions, enabling management at scale.
Why the other options are wrong
- A. Azure Blueprints orchestrates the deployment of resources and policies, but Management Groups are the hierarchical structure for applying governance across subscriptions.
- B. An Azure AD Tenant is a dedicated instance of Azure Active Directory, which manages identities, but it's not the primary construct for grouping subscriptions for policy and RBAC inheritance.
- C. Azure Resource Groups are logical containers for resources within a single subscription and cannot span multiple subscriptions for governance.
Azure Management Groups
Containers that help you manage access, policy, and compliance for multiple Azure subscriptions at scale.
- Hierarchy above subscriptions.
- Inheritance of policies and RBAC.
- Enables enterprise-scale governance.
Memory trick: Management Groups Govern Subscriptions, Subscriptions Hold Resources.