AZ-900 Describe Azure architecture and services Practice Question
A company is designing its Azure governance model. The security team must ensure that when a new management group is created beneath the root management group, any Azure Policy assignment made at the root management group is automatically applied to resources in that new management group. What should the company rely on to meet this requirement?
⚠ Common exam trap
Candidates often confuse RBAC inheritance, which governs who can act, with Azure Policy inheritance, which governs what configuration is enforced.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Policy inheritance, because policy assignments applied at a management group flow down to child management groups, subscriptions, resource groups, and resources.
Management groups exist to provide a hierarchy above subscriptions so that governance controls can be applied once and inherited everywhere below. Azure Policy assignments made at the root management group are inherited by every child management group, subscription, resource group, and resource, including scopes created later. This inheritance is the mechanism that guarantees consistent enforcement without repeated manual assignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Blueprints, because every new management group automatically receives a published blueprint definition from its parent.
Why it's wrong here
Azure Blueprints is a separate service used to package role assignments, policy assignments, and ARM templates into a repeatable definition, and it is being retired in favor of Template Specs and Deployment Stacks. Blueprints are not automatically pushed to newly created management groups, so this does not meet the stated requirement.
- ✓
Azure Policy inheritance, because policy assignments applied at a management group flow down to child management groups, subscriptions, resource groups, and resources.
Why this is correct
Azure Policy assignments are inherited down the management group hierarchy, so an assignment scoped to the root management group is evaluated against every child management group, subscription, resource group, and resource beneath it, including newly created ones. This inheritance is exactly what satisfies the requirement without any manual reassignment by the security team.
- ✗
Azure role-based access control inheritance, because RBAC role assignments at the root management group are replicated to every subscription automatically.
Why it's wrong here
RBAC role assignments do inherit down the management group hierarchy, but they control who can perform actions on resources, not which configuration rules are enforced. The scenario asks about policy assignments being applied to resources, so RBAC inheritance does not deliver the required compliance enforcement even though the inheritance behavior itself is real.
- ✗
Azure Resource Manager locks, because a read-only lock at the root management group prevents configuration drift in child scopes.
Why it's wrong here
Resource locks prevent modification or deletion of resources within their scope, but they do not push policy definitions or assignments to child scopes. A read-only lock would also block legitimate changes, and locks do not automatically propagate policy evaluation, so this option does not satisfy the governance requirement described.
Go deeper
Related to this question
Learn chapter
Zero Trust Model
Key term
Governance
Governance is the framework of policies, processes, and controls that ensures IT activities align with business goals and comply with regulations.
Key term
Azure Policy
Azure Policy is a service in Microsoft Azure that lets you create, assign, and manage rules to ensure your resources stay compliant with your company standards and service-level agreements.
About these practice questions
Courseiva writes every AZ-900 question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.