Sit above subscriptions so that Azure Policy and RBAC assignments are inherited downwards. A management group is always confined to one tenant.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Management groups in context, with comparison tables and the common traps.
Terms in this definition
- Azure Policy
Azure service that audits and enforces how resources are configured, for example their location, SKU or tags, using definitions and assignments. It neither deploys resources nor controls access.
- RBAC
Short for role-based access control: Azure role assignments, inherited downward through scopes, that decide who may perform which actions on resources. Resource location and size are outside its control.
- Management group
An Azure scope that sits over subscriptions. Policies and role assignments set there flow down to every subscription, resource group and resource it contains.
- Tenant
A trusted, dedicated Microsoft Entra ID instance that stores the users, groups and app registrations of one organisation. A subscription trusts only a single tenant, although a tenant can be trusted by several subscriptions.
Related terms
- AssignableScopes
Property of a role definition stating at which management groups, subscriptions, resource groups or resources a custom role may be assigned.
- Azure Governance Visualizer
An open-source script that produces a report on a tenant's governance setup, including management groups, policy and RBAC, and highlights Azure landing zone policies that are out of date or obsolete. The Architecture Center offers an accelerator for running it.
- Azure Landing Zone Review
A self-assessment on Microsoft Learn that checks a platform design, looking at areas such as hub networking, management groups and security baselines. It does for the platform what the Well-Architected Review does for workloads.
- azure/arm-deploy
Action deploying Bicep or ARM templates to management groups, subscriptions or resource groups from GitHub.
- Decommissioned management group
A management group for landing zones that are being retired. Subscriptions placed there are cancelled; the Cloud Adoption Framework page on management groups states that Azure removes them after 30 to 60 days, while Cost Management allows 90 days from cancellation.
- Hierarchy settings
Root management group options that decide which management group new subscriptions go into by default (the root if none is set). They also decide whether people need write permission on the root before they can create management groups.
- Minimum viable platform landing zone
Just enough platform to receive a first workload and keep it running: management groups, starter policies, a hub with hybrid connections, DNS, identities, a central log store and a firewall. You add to it as later workloads demand.
- Network manager scope
Defines which subscriptions and management groups an Azure Virtual Network Manager covers. Configuration never reaches VNets beyond it, and where two managers overlap and disagree, the higher scope takes effect.