Management Groups
The inheritance layer above subscriptions that lets one policy or role assignment apply to hundreds of subscriptions.
Readiness
0%
1h 20m baseline
Exam memorization points
- Hierarchy is tenant root management group > management groups > subscriptions > resource groups > resources.
- A management group or subscription has exactly one parent but can have many children.
- Inheritance flows downward only: RBAC and Azure Policy assigned at a management group apply to every child subscription and resource group.
- The default maximum depth is six levels of management groups below the tenant root level.
- Management groups are a tenant-level construct, created per directory, not per subscription. They cannot be moved to another tenant.
- The tenant root management group is created with the tenant and cannot be deleted.
Traps & distractors
- Forgetting the depth limit excludes the root level when the question counts levels.
- Assuming a Global Administrator can manage all management groups and subscriptions immediately. They must elevate access to gain User Access Administrator at the root scope.
- Trying to reassign a subscription to a second parent - each subscription has a single parent at a time.
- Assuming a role assignment from a management group also creates the same assignment record on the child scope. Inheritance is evaluated, not duplicated.
Suggested lab
Build a three-level governance hierarchy
Design an inheritance tree and prove inheritance with an effective-permissions check.
- 1Create management groups: mg-platform, mg-landing-zones, and children mg-corp and mg-online under landing zones.
- 2Move a test subscription under mg-corp.
- 3Assign Reader to a test user at mg-platform and verify the assignment appears as inherited on the subscription.
- 4Assign an Azure Policy definition at mg-platform and check compliance roll-up on the child subscription.
- 5Document the maximum depth against Microsoft's documented limit.
Microsoft Learn
- Organize your resources with management groupsdoc
- Search Microsoft Learn: elevate access management group permissionssearch
Live Microsoft Learn ingestion is a Sprint 2 item; until then links are curated and the search fallback always resolves.
Status
No time invested yet. Baseline assumptions only.
Self-assessed mastery
0%
Critical priority
High-yield and still weak. Study this next.
- Exam importance80% × 30% = 24.0
Learner-agnostic frequency on the real exam (4/5).
- Blueprint weight100% × 25% = 25.0
This topic's domain carries 22.5% of the exam objectives.
- Dependency leverage20% × 20% = 4.1
1 later topic depend on it.
- Current gap100% × 25% = 25.0
Readiness is 0%, so 100% of the topic is still uncovered.
Exam Priority Score = 30% importance + 25% blueprint + 20% dependency + 25% gap. Importance is exam frequency, blueprint is the domain's official exam weight, dependency is how many later topics this one unlocks, and gap is how far you currently are from ready.
Unlocks next
Baseline study time
1h 20m
Complexity
2 / 5
Remaining to target
1h 8m
Status weight
0%
Topics: hierarchy, inheritance, tenant root, governance, scope
Weak neighbours in Identities