Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsEasy

A global consulting firm uses Azure to host client applications. They need to ensure that all Azure resources deployed within specific subscriptions adhere to corporate compliance standards, such as resource tagging, allowed locations, and VM sizes. How should they implement this governance requirement across multiple subscriptions?

  1. AApply Azure Policy definitions at the Management Group level.
  2. BImplement Azure Policy assignments directly to each resource group.
  3. CUse Azure Resource Manager (ARM) templates with hardcoded compliance rules.
  4. DManually audit resources periodically and remediate non-compliant ones.
Show answer & explanation

Correct answer: A. Apply Azure Policy definitions at the Management Group level.

Applying Azure Policy at the Management Group level ensures consistent compliance enforcement across all subscriptions and resource groups nested within that Management Group, simplifying management and scaling. This is the most efficient and scalable solution for managing governance across multiple subscriptions.

Why the other options are wrong

  • B. Assigning policies to individual resource groups is less scalable and harder to manage across many subscriptions.
  • C. ARM templates define infrastructure as code but do not enforce ongoing compliance; they only apply at deployment time.
  • D. Manual auditing is reactive, error-prone, and not a scalable or automated governance solution.

Azure Policy

Azure Policy is a service in Azure that you use to create, assign, and manage policies. These policies enforce rules and effects over your resources to stay compliant with corporate standards and service level agreements.

  • Enforces organizational standards and assesses compliance at scale.
  • Evaluates resources for non-compliance and can prevent non-compliant deployments.
  • Can be applied at subscription, resource group, or management group scopes.

Memory trick: Govern your cloud kingdom from the top, ensuring all subjects follow the rules.

More Design identity, governance, and monitoring solutions questions