Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planHard

A DevOps team is responsible for managing multiple Azure subscriptions across different departments. Each department has unique compliance requirements (e.g., data residency, resource tagging, specific VM sizes). The team needs a way to centrally manage and apply these compliance rules to prevent non-compliant deployments and report on the overall compliance posture across all subscriptions. Which Azure resource hierarchy level and service combination should they use?

  1. ASubscription level with Azure Security Center (now Defender for Cloud)
  2. BResource Group level with Azure RBAC
  3. CManagement Group level with Azure Policy
  4. DIndividual Resource level with Network Security Groups (NSG)
Show answer & explanation

Correct answer: C. Management Group level with Azure Policy

Management Groups are containers that help you manage access, policy, and compliance across multiple subscriptions. By applying Azure Policy at the Management Group level, policies can be inherited by all subscriptions and resource groups within that group, enabling central management of compliance rules across departments and providing a consolidated compliance report.

Why the other options are wrong

  • A. Subscription level is better than Resource Group, but Management Groups provide an even higher level of organization for multiple subscriptions. Azure Security Center (Defender for Cloud) assesses posture but doesn't apply proactive policies across a hierarchy like Policy.
  • B. Resource Group level is too granular for managing compliance across multiple subscriptions and departments; RBAC is for authorization, not compliance enforcement.
  • D. Individual Resource level is far too granular. NSGs are for network traffic filtering, not for managing compliance rules across an organization.

Azure Management Groups

Containers that allow you to organize subscriptions into groups, applying governance conditions (like policies and access control) at scale, which are then inherited by all subscriptions and resources within that group.

  • Provides a hierarchy above subscriptions.
  • Enables enterprise-scale governance.
  • Used with Azure Policy and RBAC for inherited controls.

Memory trick: Management Groups 'Organize the Floors', and Azure Policy 'Sets the House Rules'.

More Develop a security and compliance plan questions