Container for Azure resources that also marks the edge of their billing, quotas and scale limits, governance, security and identity. Each one trusts a single Microsoft Entra tenant, and it isn't bound to any region.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure subscription in context, with comparison tables and the common traps.
Terms in this definition
- Container
Something that groups data. Blob Storage containers sit inside a storage account and hold blobs much as folders hold files; Cosmos DB containers hold items and set the scope for partitioning and throughput.
- Governance
Keeping cloud deployments in line with an organisation's rules on technology, security and compliance, helped by Azure Policy, tags and resource locks.
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- Microsoft Entra tenant
Instance of the Entra ID directory dedicated to an organisation, with an initial .onmicrosoft.com domain picked when it is created. Every Azure subscription trusts one tenant only.
- region
A provider-defined grouping in VCF Automation of Supervisors that all share one NSX Local Manager; tenants consume its compute, storage and memory via quotas set per region.
Related terms
- Active committer
How GHAS for Azure DevOps is charged. Each person counts once if they've pushed to any repository with it switched on within 90 days, even when several organisations share one Azure subscription.
- ANC
Tells Windows 365 which Azure subscription, virtual network and subnet to place Cloud PCs in (plus, where they're hybrid joined, which AD OU and domain). Provisioning policies use it, Intune checks its health at intervals of one to six hours, and you can have 50 per tenant.
- Billing policy
Ties an Azure subscription and resource group to the whole tenant or to one group, so that pay-as-you-go Copilot usage (SharePoint agents or agents in Copilot Chat, for instance) gets charged. Admins create them in the Microsoft 365 admin center, can have 50 at most, and a budget on one only raises alerts.
- Classic compute
All-purpose, jobs and pipeline compute running in your own Azure subscription, which you set up and manage yourself. Its counterpart is serverless compute, which Azure Databricks runs for you.
- Copilot pay-as-you-go billing
Charges selected Copilot services, for example SharePoint agents and agents in Copilot Chat, to a connected Azure subscription based on use. Admins configure it with billing policies, and the people using those services then don't need a Copilot licence.
- MAU
Short for monthly active users. Microsoft Entra External ID charges per distinct external user signing in within a calendar month, with 50,000 free on the core offer; an Azure subscription must be linked to the tenant.
- Pay-as-you-go billing
A consumption model for Purview charged to a linked Azure subscription. It sits on top of per-user licensing and pays for features like OCR, on-demand classification, and protecting AI apps and data beyond Microsoft 365.
- Security policies (Defender for Cloud)
The page in Defender for Cloud environment settings for assigning standards (MCSB, regulatory or custom) to an Azure subscription, AWS account or GCP project. Only initiatives can be added there, never individual policy definitions.