Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An organization manages an Azure environment with a subscription named Sub-Production that contains multiple resource groups and services.
The cloud administrator needs to grant the Tier-2 Support group permissions to manage all existing resources within Sub-Production. Additionally, any new resource groups or resources created inside Sub-Production in the future must automatically inherit these permissions without requiring additional manual role assignments.
At which scope should the administrator assign the role?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
In Azure role-based access control (Azure RBAC), a scope defines the boundary or set of resources that an access grant applies to. The subscription scope sits directly below management groups and above resource groups in the Azure resource hierarchy.
Assigning a role at the subscription scope satisfies both organizational needs:
Assigning permissions at the subscription level provides the exact boundary requested. It encompasses all existing and future resources within Sub-Production without granting unintended access to other subscriptions in the organization.