Using Azure Policy to Enforce Tag Requirements on Resource Groups Across Subscriptions
Your company wants every subscription under the Corp-MG management group to block the creation of resource groups unless the deployment includes the tags CostCenter and Environment. You need a centralized solution that is inherited by child subscriptions. What should you configure?
Quick Answer
The answer is an Azure Policy assignment at the management group scope. This is correct because Azure Policy assignments at the management group level are inherited by all child subscriptions and resource groups within that hierarchy, creating a centralized governance rule that blocks resource group creation unless the required CostCenter and Environment tags are present. On the AZ-104 exam, this scenario tests your understanding of policy inheritance and scope management—a common trap is to assign the policy at the subscription level, which would require repeating the assignment for each subscription rather than applying it once at the Corp-MG management group. Remember that management group scope enforces compliance across the entire organizational structure, making it the only solution that meets the requirement for a single, inherited rule. A helpful memory tip: "MG scope, one and done—policy flows down to every subscription and resource group under the sun."
⚠ Common exam trap
Candidates often confuse Azure Policy (which enforces rules on resource properties) with RBAC (which controls access) or locks (which prevent deletion), leading candidates to choose a permission-based or operational control instead of a governance policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An Azure Policy assignment at the management group scope
Azure Policy at the management group scope is the correct centralized solution because it enforces a policy (e.g., requiring tags) that is inherited by all child subscriptions and resource groups. This ensures that any deployment without the required tags is denied, meeting the requirement for a governance rule that applies across the entire Corp-MG hierarchy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
An Azure Policy assignment at the management group scope
Why this is correct
Management group policy assignments are inherited and can enforce required tags centrally.
- ✗
A custom RBAC role at the tenant root
Why it's wrong here
RBAC controls access permissions, not required metadata such as tags.
When this WOULD be correct
A custom RBAC role at the tenant root would be correct if the question asked for a way to grant a specific set of permissions (e.g., read-only access) to all subscriptions in the tenant, inherited by child management groups.
- ✗
A CanNotDelete lock on each subscription
Why it's wrong here
A lock does not validate whether required tags are present.
When this WOULD be correct
You need to prevent accidental deletion of a critical subscription or resource group. An exam question might ask: 'You want to ensure that a production subscription cannot be deleted by administrators. What should you configure?'
- ✗
A subscription budget alert
Why it's wrong here
A budget alert monitors spend and does not control deployment tags.
When this WOULD be correct
An exam question asks: 'You need to receive an email when spending in a subscription exceeds $10,000. What should you configure?' In that case, a subscription budget alert with an action group would be correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓An Azure Policy assignment at the management group scopeCorrect answer▾
Why this is correct
Management group policy assignments are inherited and can enforce required tags centrally.
✗A custom RBAC role at the tenant rootWrong answer — click to see why▾
Why this is wrong here
A custom RBAC role at the tenant root controls permissions (who can do what), not resource creation rules. It cannot enforce tag requirements on resource group creation.
★ When this WOULD be the correct answer
A custom RBAC role at the tenant root would be correct if the question asked for a way to grant a specific set of permissions (e.g., read-only access) to all subscriptions in the tenant, inherited by child management groups.
Why candidates choose this
Candidates may confuse RBAC with Azure Policy, thinking that a custom role can enforce compliance rules, or they may believe that tenant root scope provides inheritance similar to management groups.
✗A CanNotDelete lock on each subscriptionWrong answer — click to see why▾
Why this is wrong here
A CanNotDelete lock prevents deletion or modification of resources but does not enforce tagging requirements on new resource groups. It cannot block creation of resource groups based on missing tags.
★ When this WOULD be the correct answer
You need to prevent accidental deletion of a critical subscription or resource group. An exam question might ask: 'You want to ensure that a production subscription cannot be deleted by administrators. What should you configure?'
Why candidates choose this
Candidates may confuse locks with policy enforcement, thinking a lock can block creation or enforce conditions, when locks only protect existing resources from deletion or modification.
✗A subscription budget alertWrong answer — click to see why▾
Why this is wrong here
A subscription budget alert only notifies when spending exceeds a threshold; it does not enforce tagging requirements or block resource group creation.
★ When this WOULD be the correct answer
An exam question asks: 'You need to receive an email when spending in a subscription exceeds $10,000. What should you configure?' In that case, a subscription budget alert with an action group would be correct.
Why candidates choose this
Candidates may confuse cost management features with governance controls, thinking a budget alert can enforce tagging policies because both relate to cost control.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Dynamic Membership Groups
Key term
Subscription
A subscription is a payment model where you pay a recurring fee to access a product or service instead of buying it once and owning it forever.
Key term
Azure Policy
Azure Policy is a service in Microsoft Azure that lets you create, assign, and manage rules to ensure your resources stay compliant with your company standards and service-level agreements.
About these practice questions
This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on AZ-104
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company wants to stop users from creating resources in regions that are not approved and also require a Department tag on new resources. Which two tasks are best handled by Azure Policy? Select two.
easy- ✓ A.Restrict allowed deployment locations.
- ✓ B.Require a Department tag on resources.
- C.Give users Contributor access to the subscription.
- D.Create Microsoft Entra ID users for contractors.
- E.Place a CanNotDelete lock on every resource group.
Why A: Azure Policy can enforce organizational standards by evaluating resource properties against business rules. Option A is correct because the 'Allowed Locations' policy definition restricts users from deploying resources to any region not explicitly permitted, directly addressing the requirement to block unapproved regions. Option B is correct because the 'Require a tag and its value on resources' policy definition can enforce that a Department tag must exist on all new resources, ensuring compliance with tagging requirements.
Variation 2. A company wants to stop users from deploying resources in any region except East US and West US. Users still need to be able to create resources if they choose an approved region. Which Azure feature should the administrator use?
medium- A.Azure RBAC with a Contributor role at the subscription scope.
- ✓ B.Azure Policy with a deny effect assigned at the appropriate scope.
- C.A resource lock at the subscription level.
- D.A tag requirement in Azure RBAC.
Why B: Azure Policy with a deny effect can enforce that resource deployments are only allowed in specified regions (East US and West US) by evaluating the location property of the resource against a policy definition. When a user attempts to deploy a resource in a non-approved region, the policy engine rejects the request before any resource creation begins, ensuring compliance without blocking approved regions.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.