AZ-900 Describe Azure management and governance Practice Question
A company is adopting a landing zone approach in Azure. The governance team wants to automatically provision a standardized environment for each new Azure subscription. The environment must include: a predefined set of Azure Policy assignments (e.g., enforce resource tagging), specific RBAC role assignments for a central operations team, and a baseline resource group containing a storage account with a specific configuration. The team wants to package all these components into a single, versioned object that can be assigned to a management group and updated over time as requirements change. Which Azure governance service should the team use?
⚠ Common exam trap
A common mix-up: candidates confuse Azure Policy (which only enforces rules) with Azure Blueprints (which packages policies, roles, and resources together), or assume Management Groups can provision environments when they only provide hierarchical scope for management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Blueprints
Azure Blueprints is the correct service because it is designed to orchestrate the deployment of a repeatable, versioned environment that includes Azure Policy assignments, RBAC role assignments, and resource groups/templates as a single, composable artifact. Unlike Azure Policy alone, Blueprints can package multiple governance components together and assign them to management groups or subscriptions, with versioning support for updates over time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy
Why it's wrong here
Azure Policy is used to enforce compliance rules on existing resources, but it cannot deploy resources like storage accounts or assign RBAC roles. It only manages policy definitions and assignments, not the full set of infrastructure and roles required by the scenario.
When this WOULD be correct
A question that asks: 'Which service should be used to enforce tagging rules and audit compliance across all resources in a subscription?' would have Azure Policy as the correct answer, as it is designed for policy definition and compliance evaluation.
- ✓
Azure Blueprints
Why this is correct
Azure Blueprints enables you to define a repeatable set of Azure resources (including policies, roles, and ARM templates) that implement and adhere to your organization's standards. Blueprints are versioned and can be assigned to management groups to automatically provision the environment in all child subscriptions.
- ✗
Azure Management Groups
Why it's wrong here
Azure Management Groups provide a hierarchical structure for organizing and managing subscriptions, such as applying policies at scale. However, they do not inherently deploy resources or assign roles; they are containers that help with governance but do not provision environments.
When this WOULD be correct
A company needs to organize multiple Azure subscriptions under a common governance hierarchy, applying the same Azure Policy and RBAC assignments at the root level to all subscriptions. The team wants to structure subscriptions by department (e.g., Sales, R&D) using a parent-child relationship.
- ✗
Azure Resource Graph
Why it's wrong here
Azure Resource Graph is a service that allows you to query and explore Azure resources across subscriptions. It is used for inventory and discovery, not for provisioning or governance enforcement. It cannot deploy a standardized environment.
When this WOULD be correct
A question asks: 'Which Azure service allows you to query and discover resources across multiple subscriptions and management groups using a powerful query language?' Azure Resource Graph would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Azure BlueprintsCorrect answer▾
Why this is correct
Azure Blueprints enables you to define a repeatable set of Azure resources (including policies, roles, and ARM templates) that implement and adhere to your organization's standards. Blueprints are versioned and can be assigned to management groups to automatically provision the environment in all child subscriptions.
✗Azure PolicyWrong answer — click to see why▾
Why this is wrong here
Azure Policy only enforces rules and effects on resources (e.g., tagging), but it cannot provision resources or assign RBAC roles as part of a packaged, versioned environment. The question requires a service that deploys and orchestrates multiple resource types together.
★ When this WOULD be the correct answer
A question that asks: 'Which service should be used to enforce tagging rules and audit compliance across all resources in a subscription?' would have Azure Policy as the correct answer, as it is designed for policy definition and compliance evaluation.
Why candidates choose this
Candidates may confuse Azure Policy's ability to enforce rules with the broader orchestration capabilities of Blueprints, assuming that policy assignments alone can provision the full environment described.
✗Azure Management GroupsWrong answer — click to see why▾
Why this is wrong here
Azure Management Groups organize subscriptions hierarchically for policy and access management, but they cannot package and version a standardized environment (policies, RBAC, resources) as a single deployable object. The question requires a service that provisions and versioned components, which is Azure Blueprints.
★ When this WOULD be the correct answer
A company needs to organize multiple Azure subscriptions under a common governance hierarchy, applying the same Azure Policy and RBAC assignments at the root level to all subscriptions. The team wants to structure subscriptions by department (e.g., Sales, R&D) using a parent-child relationship.
Why candidates choose this
Candidates may confuse management groups with blueprints because both are used for governance at scale, but management groups only provide a structure for applying policies and RBAC, not for deploying and versioning a full environment.
✗Azure Resource GraphWrong answer — click to see why▾
Why this is wrong here
Azure Resource Graph is a query service for exploring resources across subscriptions, not a deployment or governance tool. It cannot provision environments, assign policies, or create resource groups.
★ When this WOULD be the correct answer
A question asks: 'Which Azure service allows you to query and discover resources across multiple subscriptions and management groups using a powerful query language?' Azure Resource Graph would be the correct answer.
Why candidates choose this
Candidates may confuse Resource Graph's ability to see resources across subscriptions with the ability to deploy or govern them, or they may think 'graph' implies a structured environment like a blueprint.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
Role
A role is a named set of permissions that can be assigned to users or groups to control access to resources in an IT environment.
Key term
RBAC
RBAC is a method of restricting network access based on the roles of individual users within an organization, where permissions are assigned to roles rather than to individuals directly.
About these practice questions
This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.