BrainyBeeBrainyBee
ExploreBlogStart Studying
HomeDesigning Microsoft Azure Infrastructure Solutions (AZ-305)Cram Sheet — Design governance
Topic Cram Sheet621 words

Cram Sheet — Design governance

AZ-305 › Unit 1 › Design governance

Cram Sheet — Design governance

Place boundaries, policy, cost ownership, compliance evidence, and privileged access at the right scope. Use this sheet after the linked lessons: it is a retrieval map and decision aid, not a substitute for the worked examples.

Cram target

Unit
1
Blueprint domain
Design identity, governance, and monitoring solutions
Decision anchors
4
Mastery standard
Recommend and reject

Decision matrix

Requirement shapeStart withQualifying rule
Enterprise hierarchyManagement groups and subscriptionsOrganise by durable governance differences
Prevent configuration driftAzure Policy and initiativesAudit first, then deny/modify/deploy with remediation
Protect lifecycle operationsResource locks and deployment stacksDo not confuse protection with authorization
Govern access lifecyclePIM, access reviews, entitlement managementRemove standing and stale access

The phrase start with matters. A default is only defensible after checking all hard constraints: region and SKU support, protocols, scale, availability, security, residency, recovery, skills, and operating ownership. When two rows appear in one scenario, compose them rather than forcing one service to solve every concern.

Fast design method

  1. Name the workload boundary and the users or systems that cross it.
  2. Extract measurable requirements: latency, throughput, volume, RTO/RPO, consistency, outage window, and retention.
  3. Mark security and governance constraints: identity, network reachability, encryption, residency, audit, and separation of duties.
  4. Select the simplest viable default from the matrix.
  5. Test it against failure domains, scale transitions, deployment, monitoring, and cost.
  6. State the nearest alternative and the one constraint that makes it weaker.
Loading Diagram...
Figure 1 — Mermaid diagram

Text equivalent: derive requirements, choose a default, qualify it against constraints, add operational and failure behaviour, then explain the trade-off.

Answer the architecture decision

For design governance, begin with this lens: Place boundaries, policy, cost ownership, compliance evidence, and privileged access at the right scope.

High-value traps

  • Tags do not inherit without policy.
  • NotActions is not an explicit deny.
  • Root-scope assignments can create exception debt.

Scenario rehearsal

An organisation asks for the capability described by the first matrix row, but also adds a strict recovery target, private connectivity, and a small operations team. Write a recommendation that identifies the core service, the supporting continuity and network controls, and the operating trade-off. Then reject the nearest service alternative using one explicit requirement. If your answer lists products without a traffic, data, identity, or recovery flow, it is incomplete.

Final-minute checklist

  • I can distinguish every service in the matrix by requirement, not logo or name.
  • I know which controls operate at identity, management, data, and network planes.
  • I check regional/SKU support and current limits when a scenario depends on them.
  • I include monitoring, health, capacity, recovery, and ownership in the recommendation.
  • I can explain why the strongest distractor fails.
Loading flashcards…

Source and freshness

Aligned to the current AZ-305 study guide, the attached Exam Ref, and the attached AZ-305 study guide corpus. Current Microsoft Learn documentation controls product availability, limits, and renamed services. Reviewed 2026-08-02.

All Designing Microsoft Azure Infrastructure Solutions (AZ-305) Study Resources

Related Notes

  • Design Governance — Topic Lesson5,083 words
  • Design Studio — Design governance732 words
  • Quick Note — Recommend a Solution for Identity Governance817 words
  • Recommend a Solution for Identity Governance — Lesson5,997 words
  • Quick Note — Recommend a Solution for Managing Compliance792 words
  • Recommend a Solution for Managing Compliance — Lesson4,603 words
  • Quick Note — Recommend a Structure for Management Groups, Subscriptions, Resource Groups, and Tagging803 words
  • Recommend a Structure for Management Groups, Subscriptions, Resource Groups, and Tagging — Lesson5,250 words
  • AZ-305 Exam Map and Design Decision Playbook652 words
  • Unit 1 Capstone — Design identity, governance, and monitoring solutions668 words
  • Unit 1 Roadmap — Design identity, governance, and monitoring solutions639 words
  • Cram Sheet — Design authentication and authorization solutions632 words

Ready to study Designing Microsoft Azure Infrastructure Solutions (AZ-305)?

Practice tests, flashcards, and all study notes — free, no sign-up.

Start Studying

Ready to study Designing Microsoft Azure Infrastructure Solutions (AZ-305)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free
Designing Microsoft Azure Infrastructure Solutions (AZ-305) ResourcesExplore All HivesBlogHome

© 2026 BrainyBee. Free AI-powered exam prep.

Loading Diagram...
Flowchart, left to right. Scenario connects to Requirements. R connects to Default service family. D connects to All hard constraints met?. F connects to Choose qualified alternative (No). F connects to Add operations and failure handling (Yes). A connects to O. O connects to Explain trade-off.

Design governance checkpoint

Card 1 of 4

Front of flashcard 1 of 4

For enterprise hierarchy, what is the default decision anchor?

easy

Management groups and subscriptions: Organise by durable governance differences.

az-305retrieval

Design governance checkpoint

Card 1

Front

For enterprise hierarchy, what is the default decision anchor?

Back

Management groups and subscriptions: Organise by durable governance differences.

Card 2

Front

For prevent configuration drift, what is the default decision anchor?

Back

Azure Policy and initiatives: Audit first, then deny/modify/deploy with remediation.

Card 3

Front

For protect lifecycle operations, what is the default decision anchor?

Back

Resource locks and deployment stacks: Do not confuse protection with authorization.

Card 4

Front

For govern access lifecycle, what is the default decision anchor?

Back

PIM, access reviews, entitlement management: Remove standing and stale access.

Design governance checkpoint

Card 1

Front

For enterprise hierarchy, what is the default decision anchor?

Back

Management groups and subscriptions: Organise by durable governance differences.

Card 2

Front

For prevent configuration drift, what is the default decision anchor?

Back

Azure Policy and initiatives: Audit first, then deny/modify/deploy with remediation.

Card 3

Front

For protect lifecycle operations, what is the default decision anchor?

Back

Resource locks and deployment stacks: Do not confuse protection with authorization.

Card 4

Front

For govern access lifecycle, what is the default decision anchor?

Back

PIM, access reviews, entitlement management: Remove standing and stale access.