AZ-900 Describe Azure management and governance Practice Question
What is the primary benefit of Azure Management Groups in a large enterprise with hundreds of subscriptions?
⚠ Common exam trap
A common mix-up: candidates confuse Management Groups with billing management or networking features, assuming they consolidate billing or enable network connectivity, when in fact their sole purpose is hierarchical governance of policy and access across subscriptions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Applying governance policies and RBAC to all subscriptions in a hierarchy at once
Azure Management Groups allow you to organize subscriptions into a hierarchy and apply governance policies (via Azure Policy) and role-based access control (RBAC) at the management group level, which then cascades down to all subscriptions and resources within that group. This enables consistent governance across hundreds of subscriptions without needing to configure each one individually, which is the primary benefit for large enterprises.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Automatically reducing the cost of Azure subscriptions
Why it's wrong here
Management groups provide a governance scope for organizing subscriptions and applying policies, but they do not have any built-in cost optimization functionality. Cost reduction requires separate tools like Azure Cost Management, budgeting, or Azure Advisor recommendations, which operate independently of management group hierarchy. Thus, while management groups help organize resources, they do not automatically lower subscription spending.
- ✓
Applying governance policies and RBAC to all subscriptions in a hierarchy at once
Why this is correct
This is a primary purpose of management groups. By placing subscriptions under a management group, you can assign Azure Policy definitions and role-based access control (RBAC) initiatives at the management group level, and those assignments are inherited by all descendant subscriptions and resources. This enables consistent governance, compliance, and access control across the entire hierarchy without needing to configure each subscription individually.
- ✗
Merging multiple subscriptions into a single billing account
Why it's wrong here
Management groups create a logical hierarchy that facilitates management and policy enforcement, but they do not merge billing entities. Billing consolidation is handled at the Azure Enterprise Agreement or Microsoft Customer Agreement level, where multiple subscriptions can be linked to a single billing account or invoice section. Management groups do not affect financial responsibility or billing relationships.
- ✗
Allowing resources in different subscriptions to share the same virtual network
Why it's wrong here
Management groups do not provide network connectivity or enable resources to share a virtual network. Cross-subscription VNet sharing is achieved through VNet peering, or by placing resources in the same VNet if the subscriptions are part of the same Azure AD tenant and the VNet resides in one subscription. Management groups are purely an organizational and governance layer, not a networking feature.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
RBAC
RBAC is a method of restricting network access based on the roles of individual users within an organization, where permissions are assigned to roles rather than to individuals directly.
Key term
Role
A role is a named set of permissions that can be assigned to users or groups to control access to resources in an IT environment.
About these practice questions
This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.