Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard

A company is restructuring its Azure environment. They need to move an existing Azure subscription, named 'Development-Subscription', from its current Management Group 'Dev-MG' to a new Management Group 'Prod-MG'. Which role is required at the 'Development-Subscription' scope to perform this move?

  1. AOwner on the 'Development-Subscription' and 'Owner' on the *source* Management Group ('Dev-MG').
  2. BOwner on the 'Development-Subscription' and 'Owner' on 'Prod-MG' and 'Dev-MG'.
  3. COwner or User Access Administrator on the 'Development-Subscription' and 'Contributor' on 'Prod-MG'.
  4. DOwner or User Access Administrator on the 'Development-Subscription' and 'Contributor' on the *target* Management Group ('Prod-MG').
Show answer & explanation

Correct answer: D. Owner or User Access Administrator on the 'Development-Subscription' and 'Contributor' on the *target* Management Group ('Prod-MG').

To move an Azure subscription between management groups, you need specific permissions. On the subscription itself, you need 'Owner' or 'User Access Administrator'. On the *target* management group ('Prod-MG' in this case), you also need 'Contributor' role to allow the subscription to be placed there.

Why the other options are wrong

  • A. Requiring 'Owner' on the source Management Group is not necessary for the move operation, and 'Owner' on the subscription alone is insufficient without permissions on the target MG.
  • B. Requiring 'Owner' on both source and target management groups is excessive. 'Contributor' on the target is sufficient, and no specific role on the source MG is required for the *move* operation.
  • C. This option is partially correct but specifies 'Contributor' on the source Management Group, which is not strictly required for the *move itself* (though you might have it for other reasons). The key is Contributor on the *target*.

Move Azure Subscription between Management Groups Permissions

To move an Azure subscription between management groups, specific RBAC permissions are required on both the subscription itself and the target management group.

  • Requires 'Owner' or 'User Access Administrator' on the subscription being moved.
  • Requires 'Contributor' role on the *target* management group.
  • No specific role is required on the *source* management group for the move operation itself.

Memory trick: Subscription needs its own key, and the new house needs to let it in.

More Manage Azure identities and governance questions