Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization manages dozens of Azure subscriptions across several business units. The cloud governance team must enforce uniform security standards and grant administrative permissions across multiple subscriptions simultaneously, without having to configure role-based access control (RBAC) and governance rules on each subscription individually.
Which Azure architectural component should the team use to apply role assignments and policies across multiple subscriptions at once?
Management groups are containers in the Azure resource hierarchy that sit above subscriptions. They provide a level of organization and governance that enables organizations to manage access, policies, and compliance across multiple subscriptions efficiently.
When an administrator assigns an Azure role-based access control (Azure RBAC) role or an Azure Policy definition at the management group scope, all subscriptions, resource groups, and resources located within that management group automatically inherit those permissions and policies. This eliminates the operational overhead of manually creating role assignments and policy bindings across individual subscriptions.
Using management groups is the recommended best practice in Azure architecture when governance and access must span across multiple subscriptions. It provides a single point of management that ensures consistency and eliminates configuration drift across enterprise workloads.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.