AZ-900 Describe Azure management and governance Practice Question
A company has multiple Azure subscriptions for different departments. The governance team needs to ensure that every new subscription is automatically provisioned with a consistent set of resources, including a predefined network topology, mandatory Azure Policy assignments (e.g., allowed locations), and specific role-based access control (RBAC) assignments for the security team. The solution must be repeatable, version-controlled, and allow the team to update the defined artifacts and apply updates to existing subscriptions. Which Azure service should the team use to define and deploy this collection of governance artifacts?
⚠ Common exam trap
It's easy for candidates to confuse Azure Policy (which only enforces rules) with Azure Blueprints (which orchestrates the deployment of policies, RBAC, and resources together), or they assume Management Groups can deploy resources when they only provide hierarchical management and policy inheritance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Blueprints
Azure Blueprints is the correct service because it enables the orchestrated deployment of a repeatable set of Azure resources, policies, and RBAC assignments as a single, version-controlled artifact. Unlike Azure Policy alone, Blueprints can include resource templates (e.g., network topology) and RBAC assignments, and it supports updating existing subscriptions by publishing new versions of the blueprint and assigning them to subscriptions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Blueprints
Why this is correct
Azure Blueprints enables the orchestrated deployment of a collection of Azure artifacts (policies, role assignments, ARM templates, resource groups) in a versioned, repeatable manner. It is the correct service for defining and applying a consistent governance baseline across subscriptions.
- ✗
Azure Policy
Why it's wrong here
Azure Policy enforces compliance rules (e.g., allowed locations or required tags) but cannot deploy network topologies or RBAC assignments as a coordinated, versioned set of artifacts. Blueprints can include policy assignments, but Policy alone is insufficient for this scenario.
When this WOULD be correct
An exam question that asks: 'Which Azure service should be used to enforce compliance rules, such as restricting resource locations or requiring specific tags, across all resources in a subscription?' would make Azure Policy the correct answer.
- ✗
Azure Management Groups
Why it's wrong here
Management Groups provide a hierarchical structure to organize subscriptions and apply policies at scale, but they do not deploy or version resources such as network topologies or RBAC assignments. They are a governance container, not a deployment tool.
When this WOULD be correct
A company needs to apply the same set of Azure Policy definitions and RBAC assignments across multiple subscriptions based on their department (e.g., all Finance subscriptions must have a specific allowed location policy). The solution must be scalable and centrally managed without deploying resources. In this case, Azure Management Groups would be correct to organize subscriptions and assign policies and RBAC at the group level.
- ✗
Azure Resource Manager templates
Why it's wrong here
ARM templates are used to deploy Azure infrastructure declaratively, but they lack built-in capabilities to include policy definitions, RBAC assignments, and versioning as a holistic governance package. Azure Blueprints can incorporate ARM templates as part of a larger set of artifacts.
When this WOULD be correct
A company needs to deploy a standardized application environment (e.g., a three-tier web app) across multiple subscriptions with consistent networking, storage, and compute resources. The solution must be repeatable and version-controlled, but does not require built-in policy or RBAC assignments as part of the deployment artifact.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Azure BlueprintsCorrect answer▾
Why this is correct
Azure Blueprints enables the orchestrated deployment of a collection of Azure artifacts (policies, role assignments, ARM templates, resource groups) in a versioned, repeatable manner. It is the correct service for defining and applying a consistent governance baseline across subscriptions.
✗Azure PolicyWrong answer — click to see why▾
Why this is wrong here
Azure Policy only enforces compliance rules (e.g., allowed locations) but cannot provision resources like network topology or assign RBAC roles; it lacks the ability to deploy a consistent set of resources across subscriptions.
★ When this WOULD be the correct answer
An exam question that asks: 'Which Azure service should be used to enforce compliance rules, such as restricting resource locations or requiring specific tags, across all resources in a subscription?' would make Azure Policy the correct answer.
Why candidates choose this
Candidates see 'mandatory Azure Policy assignments' in the question and assume Azure Policy alone can handle the entire governance deployment, overlooking that Blueprints is needed to orchestrate policies along with resource provisioning and RBAC.
✗Azure Management GroupsWrong answer — click to see why▾
Why this is wrong here
Azure Management Groups organize subscriptions hierarchically for policy and access management, but they do not provision resources or enforce consistent deployments. The question requires deploying a predefined set of resources, policies, and RBAC assignments, which is beyond Management Groups' scope.
★ When this WOULD be the correct answer
A company needs to apply the same set of Azure Policy definitions and RBAC assignments across multiple subscriptions based on their department (e.g., all Finance subscriptions must have a specific allowed location policy). The solution must be scalable and centrally managed without deploying resources. In this case, Azure Management Groups would be correct to organize subscriptions and assign policies and RBAC at the group level.
Why candidates choose this
Candidates may confuse Management Groups with Blueprints because both operate at a high level and involve policies and RBAC. They might think Management Groups can also deploy resources, not realizing they only provide a management hierarchy for applying governance, not provisioning.
✗Azure Resource Manager templatesWrong answer — click to see why▾
Why this is wrong here
Azure Resource Manager (ARM) templates can deploy infrastructure as code but lack built-in mechanisms for version-controlled, repeatable governance artifacts that can be updated and applied to existing subscriptions automatically. They do not natively support mandatory policy assignments or RBAC as part of a subscription provisioning process.
★ When this WOULD be the correct answer
A company needs to deploy a standardized application environment (e.g., a three-tier web app) across multiple subscriptions with consistent networking, storage, and compute resources. The solution must be repeatable and version-controlled, but does not require built-in policy or RBAC assignments as part of the deployment artifact.
Why candidates choose this
Candidates may think ARM templates can handle all aspects of governance because they can include policy and role definitions, but they lack the lifecycle management and subscription-level provisioning capabilities that Azure Blueprints provide.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
Blueprint
A blueprint in IT certification is a document that outlines the topics, skills, and weighting for an exam, telling you exactly what to study.
Key term
Governance
Governance is the framework of policies, processes, and controls that ensures IT activities align with business goals and comply with regulations.
About these practice questions
Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.