A platform team wants every current and future subscription under the company's Azure hierarchy to inherit Reader access for a central audit group. The team does not want to create separate assignments for each subscription. Where should the role be assigned?
Management group scope is designed for governance that must apply across multiple subscriptions, including subscriptions added later under the same hierarchy. A role assignment at that level is inherited by child subscriptions and their resources, which is ideal for broad read-only audit access.
Why this answer
Assigning the Reader role at the management group level ensures that all current and future subscriptions within that management group inherit the assignment via Azure RBAC inheritance. This meets the requirement without needing separate assignments per subscription, as role assignments flow down the hierarchy from management group to subscription to resource group to resource.
Exam trap
The trap here is that candidates may think assigning the role at one subscription will propagate to others via inheritance, but Azure RBAC inheritance is strictly hierarchical and does not apply across sibling subscriptions—only downward from a management group or parent scope.
Why the other options are wrong
Role assignments at a single subscription do not inherit to other subscriptions. The question requires a single assignment to cover all current and future subscriptions, which is only possible at the management group level.
Assigning at a resource group only grants access to resources within that group, not to all subscriptions under the management group hierarchy. The requirement is for every current and future subscription to inherit Reader access, which requires assignment at a higher scope like a management group.
Assigning at an individual resource only grants Reader access to that specific resource, not to the entire subscription or management group hierarchy. The question requires inheritance to all current and future subscriptions, which cannot be achieved at the resource level.
When would these options actually be correct?
This option would be correct if the question asked for assigning a role to a specific subscription only, without requiring inheritance to other subscriptions, and the audit team only needs access to that one subscription.
This would be correct if the question asked: 'An audit team needs to review resources within a specific resource group across multiple subscriptions, but only for that resource group. Where should Reader access be assigned?'
This would be correct if the question asked: 'An audit team needs to inspect a specific virtual machine and should have read-only access to that VM only, without access to any other resources. Where should the role be assigned?'
Why candidates pick the wrong answer
Candidates may mistakenly believe that Azure RBAC role assignments at one subscription propagate to all subscriptions in the same management group, confusing subscription-level inheritance with management group-level inheritance.
Candidates may think resource groups are the most granular scope that still allows inheritance to multiple resources, but they overlook that inheritance does not span across subscriptions or management groups.
Candidates may think that assigning at a resource is sufficient for the audit team's needs, misunderstanding that the requirement is for all subscriptions, not a single resource.