AZ-305 Practice Question: Design identity, governance, and monitoring solutions
You are designing a governance strategy for Azure resources. Your organization has multiple departments, each with its own set of Azure subscriptions. You need to enforce consistent policies across all subscriptions, such as allowed resource locations and required tags, while allowing departments to manage their own resources within those constraints. Which Azure service should you use?
⚠ Common exam trap
A common mix-up: candidates confuse Azure Policy with Azure Blueprints, as both involve governance, but Blueprints is for deploying a full environment template while Policy is for ongoing rule enforcement and compliance auditing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Policy
Azure Policy is the correct service because it enforces organizational standards and compliance rules across all Azure resources, such as allowed locations and required tags, at scale. It applies policies to management groups, subscriptions, or resource groups, ensuring consistent governance while allowing departments to manage their own resources within those constraints. Unlike Azure Blueprints, which deploys a full environment template, Azure Policy focuses solely on rule enforcement and remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Blueprints
Why it's wrong here
Azure Blueprints was a declarative orchestration service that packaged resource groups, ARM templates, policies, and role assignments into a single blueprint artifact. However, Microsoft deprecated Azure Blueprints in July 2024, directing customers to adopt Azure Policy for compliance enforcement and Deployment Stacks/ARM templates for repeatable deployments. Because Blueprints could only assign policies at creation time and did not itself evaluate ongoing compliance, it is not the correct tool for a continuous resource governance strategy.
- ✓
Azure Policy
Why this is correct
Azure Policy is the correct choice because it centralizes enforcement of resource governance rules across management groups, subscriptions, and resource groups. It evaluates resources against policy definitions using effects such as Deny, Audit, Modify, and DeployIfNotExists, and it continuously scans for drift, not just at deployment time. This lets you enforce tagging standards, restrict resource types and locations, and auto-remediate non-compliant configurations with managed identities.
- ✗
Azure Management Groups
Why it's wrong here
Azure Management Groups are hierarchical containers for organizing subscriptions, allowing you to cascade RBAC role assignments and policy definitions down to child subscriptions. While they are a necessary component of a governance architecture, they do not themselves evaluate or enforce any rule—they only act as a scope where policies and roles can be placed. Therefore, a management group alone cannot govern resource configuration; it merely provides the organizational structure.
- ✗
Azure Role-Based Access Control (RBAC)
Why it's wrong here
Azure Role-Based Access Control (RBAC) controls which security principals can perform specific actions on Azure resources through role assignments in a 'who can do what' model. It does not inspect, validate, or enforce the actual configuration of a resource, such as its public network access, encryption settings, or tagging. RBAC is essential for least-privilege access, but it complements Azure Policy rather than replacing it, because it cannot detect or block a mis-configured resource if the user has permission to deploy it.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.