Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudMedium
A global enterprise is implementing Microsoft Defender for Cloud across its diverse Azure environment, which includes multiple subscriptions organized under management groups. The enterprise needs to define a consistent security baseline and assign security policies at a high level to ensure all child subscriptions inherit these settings, while still allowing for some granular overrides at the subscription level where necessary. Which hierarchical structure in Azure should the security team primarily leverage for this purpose?
- AManagement Groups
- BSubscriptions
- CResource Groups
- DAzure Active Directory Tenants
Show answer & explanationAnswer & explanation
Correct answer: A. Management Groups
Management groups provide a level of scope above subscriptions, allowing for the application of policies, access controls, and security settings across multiple subscriptions. This enables centralized management and consistent application of security baselines while supporting inheritance and granular overrides.
Why the other options are wrong
- B. Subscriptions are individual billing and resource containers; applying policies only at this level would not ensure consistent baselines across multiple subscriptions without duplication.
- C. Resource groups are containers for resources within a subscription and cannot apply policies across multiple subscriptions.
- D. Azure Active Directory tenants manage identities and access, but directly applying security baselines to Azure resources is done via management groups and subscriptions.
Azure Management Groups
Azure Management Groups provide a way to organize subscriptions into containers, allowing for the application of governance policies, conditional access policies, and security settings at a scope above subscriptions. This enables centralized management and consistent application of baselines.
- Organize subscriptions into a hierarchy.
- Enable inheritance of policies and access controls.
- Ideal for enterprise-scale governance and security management.
Memory trick: Management groups, like a tree's main trunk, spread policies to every bunk.