A company uses Azure Management Groups to organize subscriptions. The hierarchy is: Root Management Group -> Contoso Management Group -> Sales (management group) and R&D (management group). Under Sales there are two subscriptions: Sales-Prod and Sales-Dev. Under R&D there is one subscription: R&D-Prod. The governance team assigns an Azure Policy definition that denies the creation of resources in the East US region. They assign this policy to the Contoso Management Group, but they add an exclusion for the Sales-Dev subscription. A developer in the Sales-Dev subscription attempts to create a virtual machine in the East US region. What will happen?
The creation will succeed because the Sales-Dev subscription is explicitly excluded from the policy assignment. In Azure Policy, an assignment at a management group scope applies to all child subscriptions by default, but the assignment's exclusion list can remove specific subscriptions, resource groups, or resources from evaluation. Because the Sales-Dev subscription is listed as an exclusion, the Deny effect of the policy never evaluates resources there, so the virtual machine creation is allowed.
Why this answer
Azure Policy allows exclusions at any child scope when a policy is assigned at a parent management group. The policy assigned to the Contoso Management Group denies resources in East US, but the Sales-Dev subscription is explicitly excluded from that assignment. Therefore, the developer's virtual machine creation in East US will succeed, as the exclusion overrides the deny effect for that subscription.
Exam trap
The trap here is that candidates may assume exclusions are not allowed when a policy is assigned at a higher scope, or mistakenly think that exclusions only work at the same scope as the assignment, rather than understanding that Azure Policy supports exclusions at any child scope (management group, subscription, or resource group).
Why the other options are wrong
The policy is assigned to the Contoso Management Group, but the Sales-Dev subscription is explicitly excluded from the assignment. Exclusions override inheritance, so the policy does not apply to Sales-Dev, and the VM creation succeeds.
Exclusions can be applied at the subscription level even when the policy is assigned at a management group scope, so the Sales-Dev subscription's exclusion is valid and allows the creation.
When would these options actually be correct?
This option would be correct if the policy was assigned to the Contoso Management Group without any exclusions, and a subscription under it attempted to create a resource in a denied region. In that case, all subscriptions inherit the policy and must comply.
If the policy assignment had an effect that does not support exclusions (e.g., 'Append' or 'AuditIfNotExists') or if the exclusion was applied to a resource group within a subscription that is not allowed by policy definition, then the creation would fail.
Why candidates pick the wrong answer
Candidates may mistakenly believe that policy assignments at a management group scope always apply to all descendant subscriptions without exception, overlooking the ability to exclude specific subscriptions from the assignment.
Candidates may mistakenly believe that exclusions cannot override assignments at higher scopes, or they confuse exclusion with exemption, thinking that exclusions are not allowed at subscription level for management group assignments.