AZ-900 Describe Azure management and governance Practice Question
A retail company has 50 on-premises servers in multiple branch offices that run legacy applications that cannot be migrated to Azure. The company wants to govern these servers using the same Azure Policy and tagging standards that they use for their Azure virtual machines. They also want to view these servers alongside Azure resources in the Azure portal. Which Azure service should they deploy to extend Azure management capabilities to these on-premises servers?
⚠ Common exam trap
Many candidates confuse Azure Policy (a governance service) with the ability to manage non-Azure resources, forgetting that Azure Policy can only be applied to resources already managed by Azure Resource Manager, which requires Azure Arc for on-premises servers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Arc
Azure Arc is the correct service because it extends Azure Resource Manager (ARM) control plane to on-premises servers, allowing them to be projected as Azure resources. This enables you to apply Azure Policy and tagging standards to these servers and view them alongside Azure VMs in the Azure portal, even though the legacy applications cannot be migrated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Arc
Why this is correct
Azure Arc is the correct answer because it extends the Azure control plane to on-premises infrastructure via a lightweight agent installed on each server. This enables you to manage on-premises VMs and physical servers as Azure resources, assigning Azure Policy, Azure tags, resource groupings, and using Azure Monitor for logging and telemetry alongside cloud resources. Arc effectively makes your hybrid environment a single, manageable portfolio.
- ✗
Azure Policy
Why it's wrong here
Azure Policy is a service that evaluates and enforces compliance rules against Azure resources, such as VMs or storage accounts, by blocking non-compliant actions or triggering remediation. Although Azure Policy can be extended to on-prem servers when they are onboarded to Azure Arc, Azure Policy alone has no native way to discover or communicate with machines outside of Azure. Without an Arc agent or similar bridge, Azure Policy cannot see or manage on-premises infrastructure, so it is not the service that directly enables this scenario.
When this WOULD be correct
A question asks: 'Which Azure service allows you to enforce compliance rules across your Azure resources by creating and assigning policies?' In that context, Azure Policy is the correct answer.
- ✗
Azure Management Groups
Why it's wrong here
Azure Management Groups are a hierarchical structure used to organize Azure subscriptions into logical containers for centralized governance, such as applying RBAC assignments and Azure Policy at the subscription or management-group level. They operate exclusively within the Azure tenant and have no mechanism to connect to or inventory on-premises servers. Thus, while they help manage Azure resources at scale, they are irrelevant for directly governing the 50 on-premises servers described in the scenario.
When this WOULD be correct
A company needs to apply consistent role-based access control (RBAC) and policy assignments across multiple Azure subscriptions for different departments. Azure Management Groups would be the correct service to hierarchically organize subscriptions and enforce governance at scale.
- ✗
Azure Resource Manager
Why it's wrong here
Azure Resource Manager (ARM) is the deployment and management service that provides the REST API, role-based access control, and templates for creating, updating, and deleting resources solely within Microsoft Azure. It operates on the Azure control plane and has no built-in capability to target or manage servers located on premises or in other clouds. While Azure Arc leverages ARM to represent on-prem servers as Azure resources, ARM by itself is the underlying mechanism, not the hybrid-management solution the question asks for.
When this WOULD be correct
A question asking which service provides a consistent management layer for deploying, managing, and organizing Azure resources through templates (ARM templates) and role-based access control (RBAC) would have Azure Resource Manager as the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Azure ArcCorrect answer▾
Why this is correct
Azure Arc is the correct answer because it extends the Azure control plane to on-premises infrastructure via a lightweight agent installed on each server. This enables you to manage on-premises VMs and physical servers as Azure resources, assigning Azure Policy, Azure tags, resource groupings, and using Azure Monitor for logging and telemetry alongside cloud resources. Arc effectively makes your hybrid environment a single, manageable portfolio.
✗Azure PolicyWrong answer — click to see why▾
Why this is wrong here
Azure Policy is a service to create, assign, and manage policies, but it cannot extend management capabilities to on-premises servers on its own; it requires Azure Arc to apply policies to non-Azure machines.
★ When this WOULD be the correct answer
A question asks: 'Which Azure service allows you to enforce compliance rules across your Azure resources by creating and assigning policies?' In that context, Azure Policy is the correct answer.
Why candidates choose this
Candidates may think Azure Policy can directly manage on-premises servers because the question mentions 'govern using Azure Policy,' but they overlook that Azure Arc is needed to bridge the gap.
✗Azure Management GroupsWrong answer — click to see why▾
Why this is wrong here
Azure Management Groups are used to organize and manage access, policies, and compliance across multiple Azure subscriptions, not to extend Azure management to on-premises servers.
★ When this WOULD be the correct answer
A company needs to apply consistent role-based access control (RBAC) and policy assignments across multiple Azure subscriptions for different departments. Azure Management Groups would be the correct service to hierarchically organize subscriptions and enforce governance at scale.
Why candidates choose this
Candidates may confuse Management Groups as a way to 'manage' on-premises resources because the name implies broad management capabilities, but it is limited to Azure subscription-level governance.
✗Azure Resource ManagerWrong answer — click to see why▾
Why this is wrong here
Azure Resource Manager (ARM) is the deployment and management service for Azure resources, but it does not extend management capabilities to on-premises servers. It cannot manage non-Azure resources or apply Azure Policy and tagging to on-premises machines.
★ When this WOULD be the correct answer
A question asking which service provides a consistent management layer for deploying, managing, and organizing Azure resources through templates (ARM templates) and role-based access control (RBAC) would have Azure Resource Manager as the correct answer.
Why candidates choose this
Candidates may confuse Azure Resource Manager as the overarching management plane for all Azure resources, mistakenly believing it can also manage on-premises servers if they are treated as Azure resources via some extension.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
Azure Resource Manager
Azure Resource Manager (ARM) is the deployment and management service for Azure that provides a consistent management layer for creating, updating, and deleting resources in your Azure account.
Key term
Azure portal
The Azure portal is a web-based, unified console that lets you build, manage, and monitor everything from simple web apps to complex cloud deployments using a graphical user interface.
About these practice questions
One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.