Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization operates multiple Azure subscriptions across several business units, including Finance, Marketing, and Engineering. The cloud governance team must centrally manage access control, enforce compliance rules using Azure Policy, and apply standard governance settings across all subscriptions without having to configure each subscription individually.
Which Azure architectural component should the organization implement to organize and govern these subscriptions hierarchically?
Azure Management Groups are governance containers positioned above subscriptions in the Azure resource hierarchy. They provide a level of organization and management that allows enterprises to structure, manage, and govern multiple subscriptions efficiently as a unified tree-like hierarchy.
By grouping subscriptions under management groups, the organization can attach access permissions (Azure role-based access control or Azure RBAC) and compliance policies (Azure Policy) at the management group scope. All subscriptions and child management groups placed within that structure automatically inherit those settings, fulfilling the need to govern all business units consistently without repetitive individual configurations.
Using management groups provides true at-scale governance and policy inheritance above subscriptions, which eliminates the administrative burden and potential security gaps associated with configuring subscriptions individually.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.