AZ-900 Describe Azure management and governance Practice Question
Which Azure service provides a way to enforce organizational standards and assess compliance at scale across Azure resources?
⚠ Common exam trap
AZ-900 often tests the confusion between Azure Policy and Azure Blueprints, where candidates mistakenly think Blueprints enforces compliance, but Blueprints is for deployment orchestration while Policy is for enforcement and assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Policy
Azure Policy is the service designed to enforce organizational standards and assess compliance at scale. It evaluates Azure resources against business rules and provides a compliance dashboard showing which resources are compliant or non-compliant. Policies can deny resource creation, audit changes, or deploy missing configurations, ensuring governance across subscriptions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure RBAC
Why it's wrong here
Azure RBAC (Role-Based Access Control) is an identity and access management layer that determines who can perform lifecycle operations on resources through role assignments at management group, subscription, resource group, or resource scope. It answers 'can this principal start or stop a VM or delete a resource,' not 'may this resource exist with these properties or in this location.' RBAC permissions are evaluated only against management-plane actions, whereas Azure Policy evaluates resource properties and configuration against rule definitions, so RBAC cannot enforce the organizational rules described in the question.
- ✗
Azure Blueprints
Why it's wrong here
Azure Blueprints is an orchestration and packaging service that bundles Azure Resource Manager templates, RBAC role assignments, policy definitions, and resource groups into a single assignable blueprint for creating repeatable environments. When a blueprint is assigned, the included Azure Policy assignments are pushed to the target scope, but the actual enforcement and compliance assessment are executed by Azure Policy, not by Blueprints itself. Because the question asks for the service that enforces governance rules over resource configuration, Blueprints is merely a delivery vehicle and therefore insufficient.
- ✓
Azure Policy
Why this is correct
Azure Policy is the correct service because it defines business rules as policy definitions that apply to resource types and properties, using effects such as Deny, Audit, Modify, Append, and DeployIfNotExists to govern resource configurations. Policies are assigned to scopes ranging from a management group to an entire subscription or resource group, and the service continuously scans all existing resources for compliance, marking them compliant or non-compliant. This exactly matches the requirement to enforce organizational rules and assess compliance across resources at scale rather than manage identities or provide recommendations.
- ✗
Azure Advisor
Why it's wrong here
Azure Advisor is a personalized advisory engine that analyzes your deployed Azure resources and provides best-practice recommendations in categories such as high availability, security, performance, and cost optimization. It never blocks or enforces changes; it only suggests actions you can take, so it does not assess compliance against your own organizational policies, and it cannot prevent a user from provisioning a resource that violates a rule. The question's 'enforce' and 'assess compliance' language points to Azure Policy, not Advisor.
Go deeper
Related to this question
Learn chapter
Azure Policy
Key term
Dashboard
A dashboard is a visual display of key metrics and data points that helps IT professionals monitor, analyze, and manage systems or processes in real time.
Key term
Governance
Governance is the framework of policies, processes, and controls that ensures IT activities align with business goals and comply with regulations.
About these practice questions
This AZ-900 question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.