Courseiva
Describe Azure management and governanceeasyMultiple ChoiceObjective-mapped

AZ-900 Describe Azure management and governance Practice Question

A company wants to organize their Azure subscriptions into a hierarchy to manage access policies and cost across different departments. They have three departments: Sales, Marketing, IT. What should they create first?

⚠ Common exam trap

It's easy for candidates to confuse management groups with resource groups, thinking resource groups can organize subscriptions, when in fact management groups are the only Azure construct designed to create a subscription hierarchy for cross-department governance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Management groups

Management groups are the correct first step because they allow you to organize Azure subscriptions into a hierarchy for centralized management of access policies and cost across departments. By creating a management group hierarchy (e.g., Root → Departments → Sales, Marketing, IT), you can apply Azure Policy and role-based access control (RBAC) at the management group level, which then cascades down to all subscriptions and resources within that branch. This enables consistent governance and cost tracking across the entire department without needing to configure each subscription individually.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Resource groups

    Why it's wrong here

    A resource group is a logical container that holds related resources for a single application or workload, and it lives within one subscription. Resource groups do not contain or organize subscriptions; rather, they are scoped below a subscription, and multiple resource groups exist under a single subscription, so they cannot form a hierarchy of subscriptions.

    When this WOULD be correct

    A company needs to organize resources within a single subscription by function (e.g., web apps, databases) and apply role-based access control or cost tracking at that level. They should create resource groups first.

  • Management groups

    Why this is correct

    Management groups are Azure containers that hold subscriptions, enabling you to organize them into a hierarchy for unified governance, policy assignment, and cost management. By nesting management groups, you can apply access or policies at the top level and have them inherit down to all subscriptions and their resources, making them the correct tool for hierarchical subscription organization.

  • Azure Policy

    Why it's wrong here

    Azure Policy is a service that creates, assigns, and manages rules (policy definitions) to enforce compliance and governance across your environment, such as restricting resource locations or requiring specific tags. It evaluates and audits resources against these rules, but it does not provide a structural or organizational container for subscriptions; policies are applied to a scope (management group, subscription, or resource group) rather than creating that scope.

    When this WOULD be correct

    A company needs to enforce compliance rules across all subscriptions in a department, such as requiring specific resource tags or restricting resource locations. In that scenario, Azure Policy would be the correct answer because it applies governance rules at scale.

  • Tagging

    Why it's wrong here

    Tagging attaches key-value pairs to resources or resource groups to organize them logically for cost reporting, classification, or automation, but it does not create any hierarchy. Tags do not establish parent-child relationships between subscriptions and provide no inheritance of permissions or policies, so they cannot manage subscriptions in a hierarchical structure.

    When this WOULD be correct

    A company wants to categorize resources by department for cost reporting and apply metadata to resources. They should create tags first, then assign them to resources or resource groups.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.

Management groupsCorrect answer

Why this is correct

Management groups are Azure containers that hold subscriptions, enabling you to organize them into a hierarchy for unified governance, policy assignment, and cost management. By nesting management groups, you can apply access or policies at the top level and have them inherit down to all subscriptions and their resources, making them the correct tool for hierarchical subscription organization.

Resource groupsWrong answer — click to see why

Why this is wrong here

Resource groups are containers for Azure resources, not for organizing subscriptions. They cannot create a hierarchy of subscriptions for managing access policies and costs across departments.

★ When this WOULD be the correct answer

A company needs to organize resources within a single subscription by function (e.g., web apps, databases) and apply role-based access control or cost tracking at that level. They should create resource groups first.

Why candidates choose this

Candidates may confuse resource groups with management groups because both involve organizing resources, but resource groups operate at a lower level within a subscription, not across subscriptions.

Azure PolicyWrong answer — click to see why

Why this is wrong here

Azure Policy is used to enforce compliance rules and audit resources, not to organize subscriptions into a hierarchy for access and cost management. The question specifically asks for organizing subscriptions into a hierarchy, which is the role of management groups.

★ When this WOULD be the correct answer

A company needs to enforce compliance rules across all subscriptions in a department, such as requiring specific resource tags or restricting resource locations. In that scenario, Azure Policy would be the correct answer because it applies governance rules at scale.

Why candidates choose this

Candidates may confuse policy enforcement with organizational structure, thinking that policies can define the hierarchy, or they may overestimate Azure Policy's scope, not realizing it operates on top of management groups rather than creating them.

TaggingWrong answer — click to see why

Why this is wrong here

Tagging is used for metadata and cost allocation, not for organizing subscriptions into a hierarchy. The question requires a hierarchical structure for access and cost management across departments, which management groups provide.

★ When this WOULD be the correct answer

A company wants to categorize resources by department for cost reporting and apply metadata to resources. They should create tags first, then assign them to resources or resource groups.

Why candidates choose this

Candidates may confuse tagging with organizing subscriptions because tags can group resources for cost management, but they lack the hierarchical access control needed for this scenario.

Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.