Governance
CoreAzure management groups
Governance scope above subscriptions with inherited policy and access.
Key points
- Organize subscriptions beneath the tenant root group.
- Policy and role assignments at a management group can inherit to descendant subscriptions.
- A clear hierarchy lets governance follow organizational or environment boundaries.
Best-known use cases
- Apply a policy to several production subscriptions.
- Delegate access across a subscription portfolio.
What candidates often confuse it with
- Management group vs subscription: governance container above subscriptions vs billing and resource-management boundary.
- Management group vs resource group: subscription organization vs resource lifecycle organization.
Key takeaway
Use management groups when several subscriptions need the same inherited governance or access boundary.
Related services
- Azure subscriptions
- Azure resource groups
- Azure resource tags
Relevant exam tasks
- D1.3.S3 — Apply and manage tags on resources
- D1.3.S4 — Manage resource groups
- D1.3.S5 — Manage subscriptions
- D1.3.S7 — Configure management groups