An Azure scope that sits over subscriptions. Policies and role assignments set there flow down to every subscription, resource group and resource it contains.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Management group in context, with comparison tables and the common traps.
Terms in this definition
- Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Flow
The unit of work inside a Lakeflow pipeline that takes data from a source, transforms it and lands it in a destination like a streaming table. Streaming flows either append or update, and
CREATE FLOWlets you declare a flow apart from the table it feeds. - subscription
Entitlement bought for a product under VCF 9.0 licensing, carrying a set capacity. Where active ones share the same site, unit and product, their capacity is combined into licences, which are then allocated to vCenters.
- Resource group
Container for Azure resources. Its location holds only metadata and cannot be changed afterwards, and one resource group cannot sit inside another.
- CONTAINS
Searches columns with a full-text index for words, phrases, prefixes, inflected forms or synonyms; you use it as a predicate in
WHERE.
Related terms
- Azure custom role
A role you author yourself for Azure RBAC, listing permitted and excluded control-plane and data-plane operations plus the scopes it may be assigned at. Excluded operations are simply taken out of the allowed set rather than blocked, and if the role includes data-plane operations it can't be used at management group level.
- Azure landing zone for Nonprofits
A ready-made option aimed at nonprofit organisations. You can start small on one subscription, or take a larger platform route that reuses management and connectivity subscriptions you already run; either way no management group hierarchy is set up.
- Brownfield
Azure resources built before, or outside, the landing zone architecture. The Cloud Adoption Framework's preferred way to bring them into line is to stand up the landing zone alongside and copy its management group, with policies set only to audit.
- Budget
A spending threshold you set in Cost Management for a management group, subscription or resource group. Alerts go out as real or forecast costs approach it, yet hitting the figure never halts any resource; wiring it to an action group lets automation react.
- Confidential Online
A management group in the Sovereign Landing Zone, beneath Landing zones, intended for workloads exposed to the internet that handle highly confidential data. It layers confidential computing controls for encryption in use on top of the Online policies.
- Decommissioned management group
A management group for landing zones that are being retired. Subscriptions placed there are cancelled; the Cloud Adoption Framework page on management groups states that Azure removes them after 30 to 60 days, while Cost Management allows 90 days from cancellation.
- Definition location
Where a policy definition or initiative is saved, either a management group or a subscription. Assignments can only be made beneath that point in the hierarchy, which is why widely used definitions should sit high up.
- Hierarchy settings
Root management group options that decide which management group new subscriptions go into by default (the root if none is set). They also decide whether people need write permission on the root before they can create management groups.