Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard
A company is restructuring its Azure environment. They need to move an existing Azure subscription, named 'Development-Subscription', from its current Management Group 'Dev-MG' to a new Management Group 'Prod-MG'. Which role is required at the 'Development-Subscription' scope to perform this move?
- AOwner on the 'Development-Subscription' and 'Owner' on the *source* Management Group ('Dev-MG').
- BOwner on the 'Development-Subscription' and 'Owner' on 'Prod-MG' and 'Dev-MG'.
- COwner or User Access Administrator on the 'Development-Subscription' and 'Contributor' on 'Prod-MG'.
- DOwner or User Access Administrator on the 'Development-Subscription' and 'Contributor' on the *target* Management Group ('Prod-MG').
Show answer & explanationAnswer & explanation
Correct answer: D. Owner or User Access Administrator on the 'Development-Subscription' and 'Contributor' on the *target* Management Group ('Prod-MG').
To move an Azure subscription between management groups, you need specific permissions. On the subscription itself, you need 'Owner' or 'User Access Administrator'. On the *target* management group ('Prod-MG' in this case), you also need 'Contributor' role to allow the subscription to be placed there.
Why the other options are wrong
- A. Requiring 'Owner' on the source Management Group is not necessary for the move operation, and 'Owner' on the subscription alone is insufficient without permissions on the target MG.
- B. Requiring 'Owner' on both source and target management groups is excessive. 'Contributor' on the target is sufficient, and no specific role on the source MG is required for the *move* operation.
- C. This option is partially correct but specifies 'Contributor' on the source Management Group, which is not strictly required for the *move itself* (though you might have it for other reasons). The key is Contributor on the *target*.
Move Azure Subscription between Management Groups Permissions
To move an Azure subscription between management groups, specific RBAC permissions are required on both the subscription itself and the target management group.
- Requires 'Owner' or 'User Access Administrator' on the subscription being moved.
- Requires 'Contributor' role on the *target* management group.
- No specific role is required on the *source* management group for the move operation itself.
Memory trick: Subscription needs its own key, and the new house needs to let it in.