Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard
A security architect is designing a strategy to manage security recommendations across multiple Azure subscriptions within their organization. They want to aggregate and review all security posture recommendations from Microsoft Defender for Cloud for all subscriptions under a single view and apply consistent security policies. Which Azure management construct should they leverage to achieve this centralized management?
- AResource Groups
- BVirtual Networks
- CAzure Active Directory Tenants
- DManagement Groups
Show answer & explanationAnswer & explanation
Correct answer: D. Management Groups
Management Groups provide a hierarchical structure above subscriptions, allowing for centralized governance, policy application, and security posture management (including Defender for Cloud recommendations) across multiple subscriptions.
Why the other options are wrong
- A. Resource Groups organize resources within a single subscription, not across multiple subscriptions.
- B. Virtual Networks are for network connectivity and isolation, not for hierarchical management of security policies or recommendations across subscriptions.
- C. Azure Active Directory Tenants manage identities and access, but directly applying security policies and aggregating Defender for Cloud recommendations across subscriptions is done via Management Groups.
Azure Management Groups
Containers that help you manage access, policies, and compliance across multiple Azure subscriptions, providing a level of scope above subscriptions in a hierarchy.
- Enable hierarchical organization of subscriptions.
- Allow for centralized policy and access management.
- Aggregate Defender for Cloud recommendations and Secure Score.
- Facilitate consistent governance across the enterprise.
Memory trick: To manage many subscriptions like a tree, Management Groups set policies for you and me.