Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard

A company is restructuring its Azure environment. They have a single Azure subscription, 'DevTestSubscription', which is currently under the 'Development' management group. All production workloads must reside in subscriptions under the 'Production' management group. You need to move 'DevTestSubscription' from the 'Development' management group to the 'Production' management group. What is the prerequisite for moving a subscription between management groups?

  1. AThe user performing the move must have the 'Owner' role on the subscription and the 'Contributor' role on the target management group.
  2. BThe user performing the move must have the 'Owner' role on both the source and target management groups.
  3. CThe user performing the move must have the 'Owner' role on the subscription and the 'Contributor' role on the source management group.
  4. DThe user performing the move must have the 'Owner' role on the subscription and the 'Microsoft.Management/managementGroups/write' permission at the destination and parent management group.
Show answer & explanation

Correct answer: D. The user performing the move must have the 'Owner' role on the subscription and the 'Microsoft.Management/managementGroups/write' permission at the destination and parent management group.

To move a subscription to a different management group, the user must have the Owner role on the subscription. Additionally, to perform the move, the user needs the 'Microsoft.Management/managementGroups/write' permission on both the destination management group and the parent management group of the subscription being moved. The 'Contributor' role alone on the management group is insufficient for this specific operation.

Why the other options are wrong

  • A. Contributor role on the target management group is not sufficient for moving a subscription; specific write permission is required.
  • B. Owner on management groups is too broad and not the precise requirement. The specific write permission is needed.
  • C. Contributor role on the source management group is not the primary requirement for the move operation; the destination and parent are key.

Subscription Move Permissions

Moving an Azure subscription between management groups requires specific RBAC permissions: 'Owner' on the subscription itself and 'Microsoft.Management/managementGroups/write' on the destination and current parent management groups.

  • Requires Owner role at subscription scope.
  • Requires write permission on destination management group.
  • Also requires write permission on the current parent management group.

Memory trick: Owner of the box, writer for the new shelf and the old shelf's parent.

More Manage Azure identities and governance questions