How to Effectively Use Azure Management Groups, Subscriptions, and Resource Groups

When used individually, Azure Management Groups, Subscriptions, and Resource Groups are very powerful. But when used together, they can establish the entire organizational structure of Azure.

In this article, I will explain Azure Resource Manager, Management Groups, Subscriptions and Resource Groups. I’ll show the relationship between each and provide guidance on how to most effectively use them all to organize Azure to meet the needs of your business. 

To deep dive into these topics, check out Cloud Academy’s full video-based Learning Path: AZ-103 Exam Preparation: Microsoft Azure Administrator. This Learning Path is designed to help you prepare for the AZ-103 Microsoft Azure Administrator exam, and it’s loaded with 25+ hours of content, including courses, quizzes, hands-on labs, and practices exams.

AZ-103 Exam Preparation: Microsoft Azure Administrator

Azure Resource Manager

In Azure, Subscriptions, Management Groups, and Resource Groups are all essential organizational constructs. But to understand the purpose of Azure Subscriptions and Management Groups, you need to begin by understanding the Azure Resource Management hierarchy.

What is Azure Resource Manager?

Azure Resource Manager is at the core of Microsoft Azure. It serves as an essential component of Azure deployment and provides a unified management layer regardless of the tool set used. Whether you use the Azure website, Azure CLI, Azure Powershell, or one of the many other methods for managing Azure resources, your commands all utilize Azure Resource Manager.

Understanding the Resource Manager Hierarchy

The Azure Resource Manager model uses four levels, or “scopes.” The following diagram provides an example of each of these scopes.

Azure Scope Levels

Image Source: Azure Resource Manager Overview

Azure Management Groups

What is a management group?

An Azure Management group is logical containers that allow Azure Administrators to manage access, policy, and compliance across multiple Azure Subscriptions en masse. Management groups allow you to build an Azure Subscription tree that can be used with several other Azure service, including Azure Policy and Azure Role Based Access Control. Azure Management Groups provide flexibility for organizing policy, access control, and compliance across multiple subscriptions. We can nest Azure Management Groups up to six levels deep for efficient management of resources.

Effective use of management groups

Among the multiple ways management groups can be utilized, Azure Management Groups can mirror your billing hierarchy. Often enterprises begin utilizing management groups in this method. However, the power of management groups is when you use them to model your organization. Azure Subscriptions can be grouped based on a need for common roles assigned along with Azure Policies and initiatives.

Organizing with management groups

Azure Management Groups provide a level of organization above Azure Subscriptions. If your company has more than one or two Azure Subscriptions, you will want to actively control access, policies, and compliance for those subscriptions. All subscription objects within a management group receives a copy of the role-based access control and policy settings applied to the management group. 

Root management group for each directory

Each Azure Active Directory (AD) tenant includes a top level or “root” management group. By default, only an Azure AD Global Administrator can access this root level group, and only after elevating access. The root management group has several important facts to be aware of:

  • Root management group is named Tenant root group, though the name can be changed.
  • The root management group cannot be moved or deleted
  • All management groups in the Azure AD are under the root management group.
  • All Azure users can see the root management group
  • You can only have one root management group
  • New subscriptions are automatically placed in the root management group when created.

Important facts about management groups

  • Up to 10,000 management groups are supported in a single Azure AD tenant.
  • Management group trees can support up to six levels of depth, not including the root level or the subscription level.
  • Management groups and subscriptions can only support one parent.
  • Management groups can have many children.
  • All subscriptions and management groups are within a single hierarchy in each directory. 

Limitations of management groups

Management groups have one large limitation: A management group cannot contain an Azure Resource. It can only contain other management groups or subscriptions.

Azure Subscriptions

What is an Azure Subscription?

An Azure Subscription can be defined in many ways, but at its simplest a subscription refers to the logical entity that provides entitlement to deploy and consume Azure resources. Some other ways to define an Azure Subscription:

  • A logical collection of Azure resources. Each asset in Azure is deployed to a single subscription.
  • A defined administrative security boundary that supports Role-Based Access Control.
  • A limiting factor to Azure scale (more on this below, see Subscription Limitations).
  • A deployment construct for the organization and consistency of Azure resources

Azure Subscriptions come with multiple considerations:

  • An Azure Subscription doesn’t cost anything
  • Each Azure Subscription has its own Administrators
  • Azure Subscriptions are global and can contain resources from multiple regions
  • Subscriptions can be purchased via many different methods (see Types of Subscriptions)

Microsoft’s definition of a subscription is “an agreement with Microsoft to use one or more Microsoft cloud platforms or services, for which charges accrue based on either a per-user license fee or on cloud-based resource consumption.”

How do subscriptions work?

Azure Subscriptions, at their core, are simple constructs. As stated above, an Azure Subscription can be used in multiple ways to organize and store Azure resources, and to organize resources in containers.

Types of subscriptions

There are a large number of ways to create a subscription with Microsoft Azure, I am going to attempt to list the most prevalent. Please see the Microsoft Azure Offer Details site for a complete list of subscription types.

  • Enterprise Agreement (EA) – an Enterprise Agreement is a volume licensing program offered by Microsoft. The Enterprise Agreement most often is seen in larger organizations with 500 or more users, and is a three year contract with Microsoft. The EA is one of the most common types of subscriptions. Also see Enterprise Dev/Test, which offers the same access as an Enterprise Agreement with a reduced rate for development and test workloads.
  • Pay as you go – Pay as you go is the second most common subscription type. Typically, the business will place a credit card file. Though rare, occasionally a client will pay by invoice.
  • Free Trial – Anyone can sign up for a Free Trial of Azure, which is good for 30 days. The free trial subscription includes $200 of Azure spend credits. A free trial is converted to Pay once a credit card is placed on file.
  • Cloud Solutions Partner (CSP) – CSP subscriptions are purchased through a Microsoft partner.

Subscription limitations

Azure has a large number of limitations per subscription, which are often referred to as “quotas”. Many (but not all) of the subscription limits can be raised by opening an online customer support request with Microsoft. Even so, all limits have a maximum value. Once you reach a maximum value, the only way to overcome it is multiple subscriptions. Details on most of the limits can be found on Microsoft Documentation site Azure subscription and service limits, quotas, and constraints.

Subscription design

In addition to Management Groups, subscriptions provide multiple layers to best organize Azure Resources to meet the needs of the enterprise. Ultimately, it is up to the business to determine how best to utilize Azure Subscriptions to organize Azure Resources. My advice; start simple. Generally I recommend beginning with two subscriptions, one for Production resources and one for non-production such as development and test.

How many subscriptions is too many?

As the number of Azure Subscriptions increases, so too does the management complexity and administrative overhead. With that being said, I give the same advice to everyone who asks me this question. Start as simple as possible, and expand as business needs demand. But with that advice, I also include the following caveat. Azure Azure (and your business) grow, be prepared to discover that the business has developed a requirement that will necessitate a move to additional subscriptions.

Subscription and management group hierarchy examples

Used in conjunction, Azure Subscriptions and Management Groups can be used to create an organizational hierarchy for your Azure Resources. An example hierarchy is included below.

Hierarchy of management groups and subscriptions

Image source: https://docs.microsoft.com/en-us/azure/governance/management-groups/

Azure Resource Groups

What is a resource group?

Resource groups are the lowest level of organizational scope, and are the level that contains almost all Azure Resources. Azure Resources Groups are logical collections of virtual machines, app services, storage accounts, virtual networks, web apps, Azure SQL databases, etc. Resource groups can be utilized to subdivide resources by application or environment, among the many options.

Azure Resource Groups are a useful tool for Role-Based Access Control (RBAC). This will allow you to grant user access at the group level. Resource Groups can also simplify reporting and billing.

 

Orion Withrow

Written by

Orion Withrow

Orion is a Sr. Solutions Architect, focused on Microsoft technologies for the last 15 years. He lives in Louisa, Virginia with his loving wife of 14 years, where they are devoted parents of four energetic, beautiful (and sometimes challenging) children. As parents and homeschoolers of an Autistic child, Orion and his wife are active in both Autism and Home School communities.


Related Posts

Amanda Cross
Amanda Cross
— February 12, 2021

New Content: Get Ready for the CISM Cert Exam & Learn About Alibaba, Plus All the AWS, GCP, and Azure Courses You Know You Can Count On

This month our team of intrepid certification specialists released five learning paths, seven courses, 19 hands-on labs, and three lab challenges!  One particularly interesting new learning path is Certified Information Security Manager (CISM) Foundations. After completing this learn...

Read more
  • alibaba
  • AWS
  • Azure
  • cism
  • DevOps
  • Google Cloud Platform
  • programming
Avatar
Cloud Academy Team
— January 31, 2021

Which Certifications Should I Get?

The old AWS slogan, “Cloud is the new normal” is indeed a reality today. Really, cloud has been the new normal for a while now and getting credentials has become an increasingly effective way to quickly showcase your abilities to recruiters and companies. With all that in mind, the s...

Read more
  • AWS
  • Azure
  • Certifications
  • Cloud Computing
  • Google Cloud Platform
Amanda Cross
Amanda Cross
— January 7, 2021

New Content: AWS Terraform, Java Programming Lab Challenges, Azure DP-900 & DP-300 Certification Exam Prep, Plus Plenty More Amazon, Google, Microsoft, and Big Data Courses

This month our Content Team continues building the catalog of courses for everyone learning about AWS, GCP, and Microsoft Azure. In addition, this month’s updates include several Java programming lab challenges and a couple of courses on big data. In total, we released five new learning...

Read more
  • AWS
  • Azure
  • DevOps
  • Google Cloud Platform
  • Machine Learning
  • programming
Bryony Harrower
Bryony Harrower
— November 6, 2020

WARNING: Great Cloud Content Ahead

At Cloud Academy, content is at the heart of what we do. We work with the world’s leading cloud and operations teams to develop video courses and learning paths that accelerate teams and drive digital transformation. First and foremost, we listen to our customers’ needs and we stay ahea...

Read more
  • AWS
  • Azure
  • content roadmap
  • GCP
Joe Nemer
Joe Nemer
— October 14, 2020

New Content: AWS Data Analytics – Specialty Certification, Azure AI-900 Certification, Plus New Learning Paths, Courses, Labs, and More

This month our Content Team released two big certification Learning Paths: the AWS Certified Data Analytics - Speciality, and the Azure AI Fundamentals AI-900. In total, we released four new Learning Paths, 16 courses, 24 assessments, and 11 labs.  New content on Cloud Academy At any ...

Read more
  • AWS
  • Azure
  • DevOps
  • Google Cloud Platform
  • Machine Learning
  • programming
Joe Nemer
Joe Nemer
— September 15, 2020

New Content: Azure DP-100 Certification, Alibaba Cloud Certified Associate Prep, 13 Security Labs, and Much More

This past month our Content Team served up a heaping spoonful of new and updated content. Not only did our experts release the brand new Azure DP-100 Certification Learning Path, but they also created 18 new hands-on labs — and so much more! New content on Cloud Academy At any time, y...

Read more
  • AWS
  • Azure
  • DevOps
  • Google Cloud Platform
  • Machine Learning
  • programming
Avatar
Andrew Larkin
— August 18, 2020

Constant Content: Cloud Academy’s Q3 2020 Roadmap

Hello —  Andy Larkin here, VP of Content at Cloud Academy. I am pleased to release our roadmap for the next three months of 2020 — August through October. Let me walk you through the content we have planned for you and how this content can help you gain skills, get certified, and...

Read more
  • alibaba
  • AWS
  • Azure
  • content roadmap
  • Content updates
  • DevOps
  • GCP
  • Google Cloud
  • New content
Alisha Reyes
Alisha Reyes
— August 5, 2020

New Content: Alibaba, Azure AZ-303 and AZ-304, Site Reliability Engineering (SRE) Foundation, Python 3 Programming, 16 Hands-on Labs, and Much More

This month our Content Team did an amazing job at publishing and updating a ton of new content. Not only did our experts release the brand new AZ-303 and AZ-304 Certification Learning Paths, but they also created 16 new hands-on labs — and so much more! New content on Cloud Academy At...

Read more
  • AWS
  • Azure
  • DevOps
  • Google Cloud Platform
  • Machine Learning
  • programming
Alisha Reyes
Alisha Reyes
— July 16, 2020

Blog Digest: Which Certifications Should I Get?, The 12 Microsoft Azure Certifications, 6 Ways to Prevent a Data Breach, and More

This month, we were excited to announce that Cloud Academy was recognized in the G2 Summer 2020 reports! These reports highlight the top-rated solutions in the industry, as chosen by the source that matters most: customers. We're grateful to have been nominated as a High Performer in se...

Read more
  • AWS
  • Azure
  • blog digest
  • Certifications
  • Cloud Academy
  • OWASP
  • OWASP Top 10
  • Security
  • VPCs
Alisha Reyes
Alisha Reyes
— July 2, 2020

New Content: AWS, Azure, Typescript, Java, Docker, 13 New Labs, and Much More

This month, our Content Team released a whopping 13 new labs in real cloud environments! If you haven't tried out our labs, you might not understand why we think that number is so impressive. Our labs are not “simulated” experiences — they are real cloud environments using accounts on A...

Read more
  • AWS
  • Azure
  • DevOps
  • Google Cloud Platform
  • Machine Learning
  • programming
Joe Nemer
Joe Nemer
— June 19, 2020

Kickstart Your Tech Training With a Free Week on Cloud Academy

Are you looking to make a jump in your technical career? Want to get trained or certified on AWS, Azure, Google Cloud Platform, DevOps, Kubernetes, Python, or another in-demand skill? Then you'll want to mark your calendar. Starting Monday, June 22 at 12:00 a.m. PDT (3:00 a.m. EDT), ...

Read more
  • AWS
  • Azure
  • cloud academy content
  • complimentary access
  • GCP
  • on the house
Joe Nemer
Joe Nemer
— June 12, 2020

Azure Certifications: Our Experts Explain Which Is Best for You

How do you choose an Azure certification? It can be hard to get started when choosing an Azure certification. There are so many to sift through, so many interesting options, and it requires a time commitment to just understand the cert landscape. To help guide you through the select...

Read more
  • AZ-900
  • Azure
  • Certifications