Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard

A media company uses Azure Blob Storage to store large video files. They want to prevent accidental deletion or modification of critical production assets, even by users with high privileges. While they need to retain the ability to make planned changes, they want to ensure an extra layer of protection. Which Azure governance feature should they implement?

  1. AAzure Management Groups
  2. BAzure Policy
  3. CAzure Blueprints
  4. DAzure Resource Locks
Show answer & explanation

Correct answer: D. Azure Resource Locks

Azure Resource Locks prevent accidental deletion or modification of Azure resources. They can be applied at various scopes (subscription, resource group, or individual resource) and even override permissions granted by Role-Based Access Control (RBAC), providing an essential layer of protection for critical assets.

Why the other options are wrong

  • A. Azure Management Groups provide a hierarchy for organizing subscriptions and applying governance, but don't directly prevent accidental changes to individual resources.
  • B. Azure Policy enforces standards and assesses compliance, but doesn't directly prevent accidental deletion or modification of existing resources in the way a lock does.
  • C. Azure Blueprints define and deploy consistent environments, not primarily for preventing accidental changes to deployed resources.

Azure Resource Locks

A governance feature that prevents users from accidentally deleting or modifying critical Azure resources.

  • Can be applied at subscription, resource group, or individual resource scope.
  • Overrides RBAC permissions for DELETE or READ-ONLY actions.
  • Provides an extra layer of protection against human error.

Memory trick: Resource Lock: Really Obstructs Careless Kills.

More Describe Azure management and governance questions