Microsoft Azure Fundamentals (AZ-900)Describe Azure architecture and servicesHard
An organization wants to centralize the management of all their Azure subscriptions, enforce consistent policies, and ensure compliance across different departments. They need a way to apply governance at a level above individual subscriptions. Which Azure architectural component should they use?
- AAzure Active Directory
- BManagement Groups
- CAzure Policies
- DResource Groups
Show answer & explanationAnswer & explanation
Correct answer: B. Management Groups
Management Groups are containers that help you manage access, policy, and compliance across multiple Azure subscriptions. They allow you to apply governance across all subscriptions within the management group, providing a hierarchical structure above resource groups and subscriptions.
Why the other options are wrong
- A. Azure Active Directory manages identities and access, but Management Groups provide the structural hierarchy for applying governance to subscriptions.
- C. Azure Policies are used to enforce rules, but Management Groups provide the scope for applying these policies across subscriptions.
- D. Resource Groups are logical containers for resources within a subscription, not for managing multiple subscriptions.
Management Groups
Containers that help you manage access, policy, and compliance across multiple Azure subscriptions. They provide a hierarchical structure that is above individual subscriptions.
- Organize subscriptions into a hierarchical structure.
- Apply policies and access controls at an enterprise scale.
- Inheritance of policies and RBAC roles down the hierarchy.
- Maximum of six levels of depth (including the root management group).
Memory trick: Management Groups manage many subscriptions, subscriptions manage many resources.