BrainyBeeBrainyBee
ExploreBlogStart Studying
HomeDesigning Microsoft Azure Infrastructure Solutions (AZ-305)Quick Note — Recommend a Structure for Management Groups, Subscriptions, Resource Groups, and Tagging
LO Quick Note803 words

Quick Note — Recommend a Structure for Management Groups, Subscriptions, Resource Groups, and Tagging

AZ-305 › Unit 1 › Design governance › Recommend a structure for management groups, subscriptions, and resource groups, and a strategy for resource tagging

Quick Note — Recommend a Structure for Management Groups, Subscriptions, Resource Groups, and Tagging

Azure gives architects a four-level resource hierarchy — Management Groups, Subscriptions, Resource Groups, and Resources — along with a free-form tag system that acts as a cross-cutting dimension for cost, ownership, and compliance. This lesson teaches you how to design those levels deliberately so that governance, security, and FinOps requirements propagate top-down without manual effort per subscription. The Azure Cloud Adoption Framework (CAF) and the Azure Landing Zone reference architecture are the canonical sources we align to throughout.

Retrieval target

Objective
Recommend a Structure for Management Groups, Subscriptions, Resource Groups, and Tagging
Mode
Closed-book recall
Target time
5 minutes
Escalation
Open the full lesson after a miss

Decision anchors

PromptCompact answer
Management groupA container that groups subscriptions for unified access (RBAC) and governance (Policy) management. Governance applied at a management group inherits down to every subscription inside it. Up to 10,00010{,}00010,000 per tenant, max 6 levels deep (excluding root and subscription levels). Each management group has exactly one parent.
Subscription (ARM)A unit of billing, scale, and management. Azure resource limits (e.g., 250 storage accounts) and many quotas are scoped to a subscription. A subscription is also an RBAC + Policy scope; assignments at the subscription cascade to its resource groups and resources. Each subscription has exactly one parent management group.
Resource groupA logical container for Azure resources within one subscription that share a lifecycle — created, deployed, monitored, and deleted together. Also a scope for RBAC, Policy, and tags. Resources can move between resource groups (with caveats per resource type), but a resource lives in exactly one RG at a time.
Tag (Azure resource tag)A name/value string pair attached to a resource, RG, or subscription used for filtering, cost analysis, automation, and policy targeting. Up to 50 tags per resource; values are case-insensitive but key spelling matters (Env=prod ≠ env=prod). Establish a tag taxonomy early — retrofitting tags is costly.

Read the answers once, then cover the right-hand column and reconstruct each one from the prompt. A useful answer names the requirement, the recommended control or service boundary, and the nearest alternative it rejects. If you can only recognize the answer after seeing it, retrieval is not yet secure.

Turn recall into an architecture answer

For recommend a structure for management groups, subscriptions, resource groups, and tagging, state: choose X because constraints A and B apply; reject Y because it fails C; validate with evidence D.

Ninety-second explanation

Without notes, explain:

  1. What requirement signals this learning objective rather than a neighbouring one?
  2. Which two solution families are most likely to be compared?
  3. Which hard constraint eliminates the strongest distractor?
  4. What identity, network, data, or failure boundary must appear in the design?
  5. Which operational test would prove the recommendation works?

Then compare your explanation with the full lesson. Record the missing decision rule—not merely the missed product name—in your error log.

Loading flashcards…

When to open the full lesson

Open the curriculum-linked lesson when you cannot explain a comparison, when a scenario depends on a numeric limit or SKU feature, or when the service is on a retirement path. Use current Microsoft Learn documentation for availability, limits, pricing, naming, and migration milestones; the quick note is intentionally compact.

Source and freshness

Derived from the linked AZ-305 lesson and retrieval deck, grounded in both attached course sources. Reviewed 2026-08-02. Current Microsoft documentation controls changing product contracts.

All Designing Microsoft Azure Infrastructure Solutions (AZ-305) Study Resources

Related Notes

  • Recommend a Structure for Management Groups, Subscriptions, Resource Groups, and Tagging — Lesson5,250 words
  • AZ-305 Exam Map and Design Decision Playbook652 words
  • Unit 1 Capstone — Design identity, governance, and monitoring solutions668 words
  • Unit 1 Roadmap — Design identity, governance, and monitoring solutions639 words
  • Cram Sheet — Design authentication and authorization solutions632 words
  • Design Authentication and Authorization Solutions — Lesson4,263 words
  • Design Studio — Design authentication and authorization solutions734 words
  • Quick Note — Recommend an Authentication Solution758 words
  • Recommend an Authentication Solution — Lesson4,868 words
  • Quick Note — Recommend an Identity Management Solution796 words
  • Recommend an Identity Management Solution — Lesson5,982 words
  • Quick Note — Recommend a Solution for Authorizing Access to Azure Resources745 words

Ready to study Designing Microsoft Azure Infrastructure Solutions (AZ-305)?

Practice tests, flashcards, and all study notes — free, no sign-up.

Start Studying

Ready to study Designing Microsoft Azure Infrastructure Solutions (AZ-305)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free
Designing Microsoft Azure Infrastructure Solutions (AZ-305) ResourcesExplore All HivesBlogHome

© 2026 BrainyBee. Free AI-powered exam prep.

Recommend a Structure for Management Groups, Subscriptions, Resource Groups, and Tagging — quick retrieval

Card 1 of 4

Front of flashcard 1 of 4

Management group

easy

A container that groups subscriptions for unified access (RBAC) and governance (Policy) management. Governance applied at a management group inherits down to every subscription inside it. Up to 10,00010{,}00010,000 per tenant, max 6 levels deep (excluding root and subscription levels). Each management group has exactly one parent.

management-group

Recommend a Structure for Management Groups, Subscriptions, Resource Groups, and Tagging — quick retrieval

Card 1

Front

Management group

Back

A container that groups subscriptions for unified access (RBAC) and governance (Policy) management. Governance applied at a management group inherits down to every subscription inside it. Up to 10,00010{,}00010,000 per tenant, max 6 levels deep (excluding root and subscription levels). Each management group has exactly one parent.

Card 2

Front

Subscription (ARM)

Back

A unit of billing, scale, and management. Azure resource limits (e.g., 250250250 storage accounts) and many quotas are scoped to a subscription. A subscription is also an RBAC + Policy scope; assignments at the subscription cascade to its resource groups and resources. Each subscription has exactly one parent management group.

Card 3

Front

Resource group

Back

A logical container for Azure resources within one subscription that share a lifecycle — created, deployed, monitored, and deleted together. Also a scope for RBAC, Policy, and tags. Resources can move between resource groups (with caveats per resource type), but a resource lives in exactly one RG at a time.

Card 4

Front

Tag (Azure resource tag)

Back

A name/value string pair attached to a resource, RG, or subscription used for filtering, cost analysis, automation, and policy targeting. Up to 505050 tags per resource; values are case-insensitive but key spelling matters (Env=prod ≠ env=prod). Establish a tag taxonomy early — retrofitting tags is costly.

Recommend a Structure for Management Groups, Subscriptions, Resource Groups, and Tagging — quick retrieval

Card 1

Front

Management group

Back

A container that groups subscriptions for unified access (RBAC) and governance (Policy) management. Governance applied at a management group inherits down to every subscription inside it. Up to 10,00010{,}00010,000 per tenant, max 6 levels deep (excluding root and subscription levels). Each management group has exactly one parent.

Card 2

Front

Subscription (ARM)

Back

A unit of billing, scale, and management. Azure resource limits (e.g., 250250250 storage accounts) and many quotas are scoped to a subscription. A subscription is also an RBAC + Policy scope; assignments at the subscription cascade to its resource groups and resources. Each subscription has exactly one parent management group.

Card 3

Front

Resource group

Back

A logical container for Azure resources within one subscription that share a lifecycle — created, deployed, monitored, and deleted together. Also a scope for RBAC, Policy, and tags. Resources can move between resource groups (with caveats per resource type), but a resource lives in exactly one RG at a time.

Card 4

Front

Tag (Azure resource tag)

Back

A name/value string pair attached to a resource, RG, or subscription used for filtering, cost analysis, automation, and policy targeting. Up to 505050 tags per resource; values are case-insensitive but key spelling matters (Env=prod ≠ env=prod). Establish a tag taxonomy early — retrofitting tags is costly.