Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Scope in context, with comparison tables and the common traps.
Terms in this definition
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- Policy assignment
What makes a policy definition or initiative take effect: it targets a management group, subscription or resource group, supplies parameter values, exclusions, an enforcement mode and non-compliance messages, and starts a compliance scan.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Resource group
Container for Azure resources. Its location holds only metadata and cannot be changed afterwards, and one resource group cannot sit inside another.
- subscription
Entitlement bought for a product under VCF 9.0 licensing, carrying a set capacity. Where active ones share the same site, unit and product, their capacity is combined into licences, which are then allocated to vCenters.
- Management group
An Azure scope that sits over subscriptions. Policies and role assignments set there flow down to every subscription, resource group and resource it contains.
- Flow
The unit of work inside a Lakeflow pipeline that takes data from a source, transforms it and lands it in a destination like a streaming table. Streaming flows either append or update, and
CREATE FLOWlets you declare a flow apart from the table it feeds.
Related terms
- Activity log alert
Alert rule without state that triggers on a matching Activity log event, deleting a management lock for instance. A scope, a condition and an action group are required; a Log Analytics workspace is not.
- Administrative unit
Used to confine a role assignment to a subset of a Microsoft Entra directory, such as just one region's users for a local helpdesk. A unit holds users, groups or devices; units cannot be nested, and including a group does not make its individual members part of the scope.
- Agentless discovery for Kubernetes
Capability in Defender CSPM and Defender for Containers that inventories Kubernetes clusters and assesses their posture through APIs, using the Kubernetes Agentless Operator role. Pod admission and blocking are outside its scope.
- Alert rule
Azure Monitor definition made up of a scope naming the target resources, a condition setting the signal and logic, and optionally action groups. A separate rule is needed for every signal that has different recipients.
- Application ID URI
Set on the Expose an API page, defaulting to
api://<application-client-id>, this globally unique value names a web API. Prefixing it to a scope name gives the complete scope string. - Architecture Vision
Produced during Phase A and revisited in Phase E, this brief outline covers the Target Architecture, the business value it offers and the change it will cause. It acts as an aspiration while also limiting the scope of later detailed work.
- Azure Monitor Private Link Scope
Azure resource linking Azure Monitor resources to private endpoints. Networks sharing one DNS should use a single scope, and peered VNets can use the same endpoint.
- Azure RBAC
Azure's model for granting access: built-in or custom roles are assigned at a scope to users, groups or managed identities. Calling Foundry keylessly with Entra ID requires a data-plane role, for example Foundry User (formerly Azure AI User) or Cognitive Services OpenAI User.