Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization operates multiple Azure subscriptions across different business units. The IT security team needs to establish a centralized governance strategy that automatically enforces compliance standards and Role-Based Access Control (RBAC) permissions across all subscriptions and their underlying resources.
Which level of the Azure management hierarchy should the security team use to apply these policies and access controls?
Management groups are containers in Azure that sit above subscriptions in the resource hierarchy. They provide a unified governance scope that allows organizations to manage access policies, compliance rules, and security controls across multiple Azure subscriptions efficiently.
By assigning Azure Policy definitions and Azure Role-Based Access Control (RBAC) roles at the management group level, all configurations and permissions are automatically inherited by:
This inheritance ensures that centralized corporate standards and access boundaries are applied universally without requiring repetitive configuration on each subscription.
Applying governance at the management group scope eliminates administrative overhead and prevents configuration drift across multiple subscriptions, ensuring all resources remain consistently secure and compliant from the top down.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.