AZ-900 Describe Azure management and governance Practice Question
A multinational company uses Azure management groups to organize its subscriptions. The company has a root management group (tenant root group) containing three child management groups: 'Finance', 'HR', and 'IT'. Each child management group contains multiple subscriptions. The global governance team needs to enforce an Azure Policy that restricts all resource deployments across every subscription in the organization to only the 'West US' and 'East US' regions. The policy must automatically apply to any new subscriptions that are created under any management group in the future. The team wants to assign the policy once and have it affect all current and future subscriptions with minimal administrative overhead. At which Azure scope should the team assign the policy?
⚠ Common exam trap
Many candidates think assigning at the child management group level is sufficient, but they overlook that the root management group provides a single assignment point that automatically covers all current and future subscriptions across the entire organization with minimal overhead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The root management group
Assigning the policy to the root management group ensures it is inherited by all child management groups (Finance, HR, IT) and their subscriptions, including any new subscriptions created in the future. This approach enforces the allowed regions policy across the entire tenant with a single assignment, minimizing administrative overhead. Azure Policy inheritance flows from the root management group down through all levels of the hierarchy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Each subscription individually
Why it's wrong here
Assigning the policy to each subscription individually would require many assignments and would not automatically apply to new subscriptions unless the team also updates the assignments. This is not the most efficient approach for a single, organization-wide policy.
When this WOULD be correct
If the question specified that the policy should only apply to a specific set of existing subscriptions and not to any future subscriptions, and the team is willing to manage each subscription separately, then assigning to each subscription individually would be correct.
- ✓
The root management group
Why this is correct
Assigning the policy at the root management group scope applies it to all child management groups and all subscriptions within them, including any new subscriptions created in the future. This is the correct approach for a single assignment that covers the entire organization.
- ✗
Each child management group (Finance, HR, IT) individually
Why it's wrong here
While assigning to each child management group would cover their respective subscriptions, it requires three separate assignments and will not automatically cover any additional management groups added later. The question specifies assigning the policy once.
When this WOULD be correct
If the company had separate compliance requirements for each department (e.g., Finance must only deploy in West US, HR in East US, IT in both), assigning the policy at each child management group would enforce distinct policies per department.
- ✗
A single resource group
Why it's wrong here
Assigning the policy at a resource group scope only affects resources within that specific resource group, not the subscriptions or management groups. This would not meet the requirement to restrict deployments across the entire organization.
When this WOULD be correct
A company needs to apply a specific policy (e.g., requiring a particular tag) only to resources within a specific project or department that are contained in a single resource group. The policy should not affect other resource groups or subscriptions.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓The root management groupCorrect answer▾
Why this is correct
Assigning the policy at the root management group scope applies it to all child management groups and all subscriptions within them, including any new subscriptions created in the future. This is the correct approach for a single assignment that covers the entire organization.
✗Each subscription individuallyWrong answer — click to see why▾
Why this is wrong here
Assigning the policy to each subscription individually would not automatically apply to new subscriptions, requiring manual reapplication and increasing administrative overhead, which contradicts the requirement for minimal overhead and automatic enforcement.
★ When this WOULD be the correct answer
If the question specified that the policy should only apply to a specific set of existing subscriptions and not to any future subscriptions, and the team is willing to manage each subscription separately, then assigning to each subscription individually would be correct.
Why candidates choose this
Candidates may think that policies must be assigned directly to the resource they affect (subscriptions) and overlook inheritance from higher scopes like management groups.
✗Each child management group (Finance, HR, IT) individuallyWrong answer — click to see why▾
Why this is wrong here
Assigning the policy to each child management group individually would not automatically apply to new subscriptions created under a different child management group or under the root, requiring repeated assignments and increasing administrative overhead.
★ When this WOULD be the correct answer
If the company had separate compliance requirements for each department (e.g., Finance must only deploy in West US, HR in East US, IT in both), assigning the policy at each child management group would enforce distinct policies per department.
Why candidates choose this
Candidates may think that since the company is organized into child management groups, assigning the policy at that level is sufficient and more targeted, overlooking the need for organization-wide enforcement and automatic coverage of future subscriptions.
✗A single resource groupWrong answer — click to see why▾
Why this is wrong here
Assigning the policy to a single resource group would only affect resources within that group, not all subscriptions across the organization. The requirement is to enforce the policy across every subscription, including future ones, which requires a higher-level scope like the root management group.
★ When this WOULD be the correct answer
A company needs to apply a specific policy (e.g., requiring a particular tag) only to resources within a specific project or department that are contained in a single resource group. The policy should not affect other resource groups or subscriptions.
Why candidates choose this
Candidates may think that assigning at a resource group is sufficient because it's a common scope for policies, but they overlook the need to cover all subscriptions and future subscriptions across the entire organization.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
Management group
A Management group is a container in Microsoft Azure that helps you organize and manage access, policies, and compliance across multiple Azure subscriptions.
Key term
Azure Policy
Azure Policy is a service in Microsoft Azure that lets you create, assign, and manage rules to ensure your resources stay compliant with your company standards and service-level agreements.
About these practice questions
One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.