Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard
A global organization is restructuring its Azure AD tenant and needs to implement a solution that allows different departments to manage their own specific sets of Azure resources (e.g., VMs, storage accounts) without granting them excessive permissions over the entire subscription. They require a hierarchical structure for organizing resources and applying policies, ensuring that permissions inherited from higher levels can be overridden or refined at lower levels. Which Azure feature is best suited for this organizational and access control requirement?
- AAzure AD Roles
- BAzure AD Administrative Units
- CAzure Resource Groups
- DAzure Management Groups
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Management Groups
Azure Management Groups provide a hierarchical structure above subscriptions, allowing for the organization of subscriptions into groups. This enables the application of governance policies and access controls (like RBAC) at a higher level, which then flow down to the subscriptions and resources within them. This allows departments to manage their own resources within their assigned management groups while adhering to overarching organizational policies.
Why the other options are wrong
- A. Azure AD Roles define permissions within Azure AD itself, not for organizing and managing Azure resources hierarchically across subscriptions.
- B. Azure AD Administrative Units are used to group users or groups in Azure AD to delegate administrative tasks within the directory, not for organizing Azure resources.
- C. Resource Groups are used to logically group related Azure resources within a subscription, but they don't provide a hierarchy *above* subscriptions.
Azure Management Groups
Containers that help you manage access, policy, and compliance across multiple Azure subscriptions, providing a level of organization above subscriptions.
- Form a hierarchy to organize subscriptions.
- Allow application of policies and RBAC roles that inherit down.
- Enable centralized governance for large-scale Azure deployments.
Memory trick: Management Groups are the organizational trees for your Azure subscriptions.