Azure management groups & subscriptions Flashcards

(42 cards)

1
Q

What are Azure management groups?

A

Azure management groups provide a governance scope above subscriptions, allowing efficient management of access, policies, and compliance across multiple Azure subscriptions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How do management groups affect governance conditions?

A

Governance conditions applied to a management group cascade by inheritance to all associated subscriptions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is required for subscriptions within a management group?

A

All subscriptions within a single management group must trust the same Microsoft Entra tenant.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What can be applied to a management group to control VM creation?

A

A policy can be applied to limit the regions available for virtual machine (VM) creation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the maximum depth of a management group tree?

A

A management group tree can support up to six levels of depth.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the role of the root management group?

A

The root management group allows for the application of global policies and Azure role assignments at the directory level.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the display name of the root management group by default?

A

The default display name is ‘Tenant root group’.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can the root management group be moved or deleted?

A

No, the root management group cannot be moved or deleted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What happens during the initial setup of management groups?

A

The root management group is created, and all existing subscriptions become children of this root management group.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Azure RBAC in the context of management groups?

A

Azure RBAC supports resource access and role definitions, allowing permissions to be inherited down the hierarchy from management groups.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How can management groups be audited?

A

Management groups can be audited using Azure Monitor activity logs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are some key considerations when using subscriptions?

A

Subscriptions serve as boundaries for Azure Policy assignments, management boundaries for governance, and can support isolation of workloads.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the purpose of establishing separate platform subscriptions?

A

Separate platform subscriptions can support management, connectivity, and identity when required.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is subscription vending?

A

Subscription vending is the process of automating the creation of subscriptions for application teams via a request workflow.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the benefits of subscription vending?

A
  • Streamlined process for requesting subscriptions
  • Improved velocity for application teams
  • Efficient governance over application landing zones
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a critical aspect of managing costs in large Azure environments?

A

Establishing a chargeback model for better distribution of costs across the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What should be included in the requirements gathered at subscription intake?

A
  • Anticipated budgets
  • Subscription owners
  • Networking expectations
  • Business criticality & confidentiality classification
18
Q

Fill in the blank: Every directory has a single top-level management group called the _______.

A

root management group

19
Q

True or False: All Azure customers can manage the root management group.

20
Q

What is a key recommendation for subscription management?

A

Treat subscriptions as a unit of management that aligns with your business needs and priorities.

21
Q

What should be done to ensure policy compliance in subscriptions?

A

Perform regular access reviews and remediate when necessary.

22
Q

What is the initial step in the subscription deployment pipeline?

A

Gather requirements at intake.

23
Q

What information should be included in subscription requirements?

A
  • Anticipated budgets
  • Subscription owners
  • Networking expectations
  • Business criticality & confidentiality classification
24
Q

Who assumes control of the subscription request process after submission?

A

The platform team.

25
What does subscription vending provide for application teams?
A standard process for requesting a subscription.
26
What should be avoided in a single routing domain?
Overlapping IP addresses.
27
What tool should be integrated into the subscription vending process for IP address assignment?
IP address management (IPAM) tool.
28
What autonomy should be granted to application teams?
Rights to create subnets and some virtual networks in the subscription.
29
What should the platform team enforce regarding virtual networks?
Networking governance.
30
What are two methods for enforcing virtual network governance?
* Azure policy assigned to the management group hierarchy * Azure Virtual Network Manager and Security Admin Rules
31
What should the platform team use to determine subscription placement?
Networking and governance requirements.
32
What helps organize and govern subscriptions and workload deployments?
Management groups.
33
What are the two key aspects that automation should be flexible enough to handle?
* Deploy multiple subscriptions * Adapt to subscription service limits
34
Why might some workloads require several subscriptions?
Some workloads have several instances separated by subscription or SaaS architectures using dedicated resources per customer.
35
What should be done after provisioning if a quota increase is needed?
Request quota increases manually using the Azure portal or automate the process using available APIs.
36
True or False: The platform team should always create virtual networks that peer to a central hub.
True.
37
Fill in the blank: The intake process should give the platform team enough information to place the workload in the _______.
management group hierarchy.
38
What should be done if a quota request fails?
Run a script to handle any errors.
39
What is the based management group hierarchy?
40
What is the FW group hierarchy?
41
What is the FW tagging strategy?
42
what is the FW standard dev env?