Question 870 of 981
AZ-900 Describe Azure management and governance Practice Question
A large enterprise has multiple Azure subscriptions for different departments. The central IT team wants to enforce a policy that restricts the Azure regions where resources can be deployed. The policy must automatically apply to all existing subscriptions and to any new subscriptions created in the future, without requiring manual assignment to each subscription individually. Which Azure feature should the central IT team use to achieve this hierarchical governance?
⚠ Common exam trap
Test-takers frequently confuse Azure Policy (which enforces rules) with the hierarchical structure needed to apply those rules broadly; Azure Policy alone requires manual assignment, whereas Management Groups enable automatic inheritance across subscriptions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Management Groups
Azure Management Groups provide a hierarchical structure above subscriptions, allowing policies (like region restrictions) to be assigned at the management group level. This inheritance ensures the policy automatically applies to all existing subscriptions within the group and to any new subscriptions added later, without manual per-subscription assignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Management Groups
Why this is correct
Correct. Management Groups allow you to assign Azure Policy at a high level (e.g., root management group) and have that policy automatically apply to all child subscriptions, including future subscriptions, ensuring consistent governance across the entire hierarchy.
- ✗
Azure Blueprints
Why it's wrong here
Incorrect. Azure Blueprints are used to define a repeatable set of Azure resources (like policies, RBAC, templates) for deploying environments, but they do not inherently automatically apply policies to all subscriptions in a hierarchy; they require explicit assignment and do not provide automatic cascading for new subscriptions.
When this WOULD be correct
A question asking for a way to package and deploy a consistent set of Azure resources, policies, and role assignments across multiple subscriptions, where each deployment is a separate instance that can be versioned and updated, would make Azure Blueprints the correct answer.
- ✗
Azure Resource Groups
Why it's wrong here
Incorrect. Azure Resource Groups are logical containers used to organize and manage related resources, but each resource group is scoped to a single Azure subscription. They cannot span subscriptions or provide any inheritance mechanism, so assigning policies to a resource group only affects resources within that group, never across multiple subscriptions. Consequently, resource groups offer no capability for centralized, cascading policy enforcement across an enterprise's entire subscription hierarchy.
When this WOULD be correct
A question asks: 'Which Azure feature should be used to organize and manage related resources for an application, such as applying role-based access control and tags to all resources in a single deployment?'
- ✗
Azure Policy alone assigned to each subscription
Why it's wrong here
Incorrect. While Azure Policy is the correct tool for enforcing rules, assigning it individually to each subscription does not automatically cover new subscriptions. This approach requires manual effort and does not achieve the desired hierarchical, automatic cascading effect.
When this WOULD be correct
If the question required applying a specific policy to a single subscription or a known set of subscriptions without needing automatic inheritance to future subscriptions, then assigning Azure Policy directly to those subscriptions would be correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Azure Management GroupsCorrect answer▾
Why this is correct
Correct. Management Groups allow you to assign Azure Policy at a high level (e.g., root management group) and have that policy automatically apply to all child subscriptions, including future subscriptions, ensuring consistent governance across the entire hierarchy.
✗Azure BlueprintsWrong answer — click to see why▾
Why this is wrong here
Azure Blueprints are used to orchestrate the deployment of resource templates and policies, but they require manual assignment to each subscription or management group and do not automatically apply to future subscriptions without explicit assignment.
★ When this WOULD be the correct answer
A question asking for a way to package and deploy a consistent set of Azure resources, policies, and role assignments across multiple subscriptions, where each deployment is a separate instance that can be versioned and updated, would make Azure Blueprints the correct answer.
Why candidates choose this
Candidates may confuse Blueprints with Management Groups because both involve governance and policies, but Blueprints are more about repeatable deployment templates rather than hierarchical policy inheritance.
✗Azure Resource GroupsWrong answer — click to see why▾
Why this is wrong here
Azure Resource Groups are logical containers for resources but do not provide hierarchical governance across multiple subscriptions or enforce policies automatically on new subscriptions.
★ When this WOULD be the correct answer
A question asks: 'Which Azure feature should be used to organize and manage related resources for an application, such as applying role-based access control and tags to all resources in a single deployment?'
Why candidates choose this
Candidates may confuse Resource Groups with management groups because both involve grouping, but Resource Groups lack the subscription-level hierarchy and policy inheritance needed for enterprise-wide governance.
✗Azure Policy alone assigned to each subscriptionWrong answer — click to see why▾
Why this is wrong here
Assigning Azure Policy to each subscription individually does not automatically apply to new subscriptions; it requires manual assignment per subscription, failing the requirement for automatic, hierarchical governance across all existing and future subscriptions.
★ When this WOULD be the correct answer
If the question required applying a specific policy to a single subscription or a known set of subscriptions without needing automatic inheritance to future subscriptions, then assigning Azure Policy directly to those subscriptions would be correct.
Why candidates choose this
Candidates may think Azure Policy is the only feature needed for enforcement, overlooking that Management Groups provide the hierarchical structure to automatically inherit policies across all subscriptions.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.