A Complete Governance Design Guide with Policy, Management Groups, and Cost Management

AZ-305 governance essentials: designing Management Group hierarchies, the five Azure Policy effects (Deny/Audit/Modify/Append/DeployIfNotExists), tagging strategies, Cost Management

AZ-305 governance and compliance design goes beyond memorization — it demands the ability to judge which tool fits which situation. Management Group hierarchy design, Azure Policy effect selection, cost governance, tagging strategies, and IaC are all deeply intertwined topics that appear together in exam questions. This post analyzes 37 actual exam questions and distills the most commonly tested patterns and decision criteria.

---

 

Management Groups and Subscription Hierarchy Design

A Management Group is a container that groups your Azure environment from a governance perspective. The hierarchy looks like this:

Policies and roles assigned at a higher tier are automatically inherited by every tier below it. If you apply an "Allow Korea Central only" policy to the Production Management Group, all three subscriptions beneath it will be governed by that policy. The sibling Development Management Group will not be affected.

When a Management Group hierarchy question appears on the exam, the first thing to verify is: "Is the target subscription a descendant of the policy-assignment node?" Even if two subscriptions belong to the same tenant, if they sit in different Management Group branches, policies will not cross over.

Resource selectors do not expand scope — they filter which resources within an already-defined policy scope are evaluated. Azure Policy assignment scope is limited to three levels: Management Group, Subscription, or Resource Group. You cannot assign a policy to an individual resource or to an Entra ID tenant as a unit.

---

 

Azure Policy and Initiatives

Azure Policy is a system that automatically enforces rules. If RBAC controls "who can do what," then Policy controls "where, how, and under what conditions deployments can happen."

The Five Policy Effects

| Effect | Behavior | Primary Use Case | |--------|----------|-----------------| | Deny | Immediately rejects the deployment request at the ARM level | Block unauthorized regions or resource types | | Audit | Records non-compliance without blocking | Assess impact scope during early policy rollout | | Append | Adds new values alongside existing ones (no overwrite) | Simple tag addition when existing values must be preserved | | Modify | Adds or changes existing properties and tags + remediation support | Auto-correct tags, inherit resource group tags | | DeployIfNotExists | Automatically deploys a related resource when a configuration is missing | Auto-enable TDE, auto-install agents |

Modify and Append are easy to confuse. Whenever you see "modify existing resource tags and apply retroactively to existing resources," always choose Modify. Append cannot overwrite existing values and does not support remediation tasks.

DeployIfNotExists policies must include . This grants the Managed Identity the RBAC role needed to modify the target resource. The entity performing the remediation is the System-assigned Managed Identity linked to the policy assignment — not a human account. For minimal-privilege tasks like tag changes, assigning only the Tag Contributor role is sufficient.

An initiative bundles multiple policies into a single package. If you group a "region restriction policy" and a "VM size restriction policy" into one initiative, assigning that initiative once to a subscription applies both policies simultaneously.

Policy evaluations run automatically every 24 hours by default. For immediate evaluation, use via the REST API or run . For instant notifications triggered by non-compliance events, combine Azure Event Grid with Logic Apps.

!The 5 Azure Policy effects

Cost Governance and Cost Management

If you need to track costs per project across 20 or more subscriptions without restructuring the subscription layout, tag every resource with keys like , , and , then filter costs by tag value in Microsoft Cost Management.

The Budget feature in Cost Management sends automatic email or Action Group alerts when actual or forecasted costs hit a configured threshold. You can set up to five thresholds. Azure Advisor offers cost-saving recommendations but does not provide budget-overage alerts.

For workloads that run 24/7, consider Reserved Instances. With a one-year or three-year commitment, you can save up to 72% compared to pay-as-you-go pricing on VMs, SQL Database, App Service, and other services — with no impact on availability or SLA. Spot VMs can cut costs by up to 90%, but Azure can terminate them at any time, making them unsuitable for always-on production workloads.

---

 

Tagging Strategy and Resource Locks

Tags work like sticky notes attached to resources. You attach key-value pairs such as and to carry metadata. One important behavior to keep in mind: tags do not automatically inherit from parent to child tiers. Tagging a resource group does not automatically tag the resources inside it.

To enforce mandatory tags on all resources, use both the Deny effect (block new deployments missing the tag) and the Modify effect (retroactively fix existing resources). The built-in policy "Inherit a tag from the resource group" also uses the Modify effect to propagate tags automatically.

Resource Locks protect production resources from accidental deletion or modification.

Delete lock: blocks deletion only; configuration changes are still allowed. ReadOnly lock: blocks all write operations — neither modification nor deletion is possible.

Resource Locks are independent of RBAC. Even a user with Owner rights cannot delete or modify a locked resource. If you need to prevent a specific resource action (for example, blocking public IP address assignment) even from Contributors, use Azure Policy Deny — not a lock.

---

 

Service Comparison Tables

Policy Effect Decision Guide

| Scenario | Chosen Effect | Reason | |----------|--------------|--------| | Block deployments to unauthorized regions | Deny | Preventive control at the ARM level | | Identify non-compliant resources without blocking | Audit | Detection only, no enforcement | | Inherit resource group tags to child resources | Modify | Modifies existing properties + remediation | | Retroactively apply missing tags to existing resources | Modify | Supports remediation tasks | | Auto-install diagnostic agent on VM creation | DeployIfNotExists | Automatically deploys missing resource/config | | Auto-enable TDE on SQL Database | DeployIfNotExists | Deploys missing config + remediation | | Block deployment of resources with no tags | Deny | Preventive control |

Governance Tool Comparison

| Tool | Core Role | Limitation | |------|-----------|-----------| | Azure Policy | Evaluate and enforce compliance (condition control) | Cannot assign roles or deploy ARM templates | | Azure RBAC | Control user/group operation permissions | Cannot restrict deployment conditions (region, SKU) | | Azure Blueprints | Package of Policy + roles + ARM + RG | Cannot be shared across tenants | | Resource Lock | Block deletion and modification (including Owners) | Cannot detect non-compliance or auto-remediate | | Cost Management | Cost tracking, budgets, and alerts | Cannot control resource deployment |

---

 

Commonly Confused Decision Points on the Exam

Scenario 1: A resource group location policy is set, but resources still deploy to other regions

The resource group location policy only controls which region the resource group itself is created in. Services like App Service or SQL Database can be deployed to a different region than their resource group. You need to add a separate Deny policy scoped at the subscription level that targets resource location. The built-in policy "Allowed locations" controls both the resource group and the individual resource locations simultaneously.

Scenario 2: Calculating minimum Blueprints definitions and assignments

N tenants + minimum definitions → N definitions (Blueprints cannot cross tenant boundaries) M subscriptions + minimum assignments → M assignments (each assignment applies 1:1 per subscription)

Within a single tenant, one definition can have multiple assignments targeting different subscriptions. Across different tenants, you must create a separate definition for each tenant.

Scenario 3: Preventive control vs. reactive detection

When you see "prevent the deployment itself," choose Azure Policy Deny. The Microsoft Defender for Cloud compliance dashboard is a reactive tool — it surfaces violations after deployment has already occurred. To stop something before it deploys (preventive), Azure Policy Deny is the only option.

Scenario 4: Centrally managing multiple customer tenants

When an MSP needs to manage resources across multiple customer tenants from a single console in their own tenant, use Azure Lighthouse. It enables cross-tenant access via Azure Resource Manager delegation with no agent installation. Azure Arc is a tool for onboarding on-premises and multi-cloud resources into Azure — a different purpose entirely.

---

 

Practical Tips

Design Management Groups based on policy-sharing patterns rather than org-chart structure. Group subscriptions that share the same rules under the same Management Group. Place only the minimum mandatory security baselines in the Root Management Group — rules that must apply to the entire organization.

When introducing a new policy, it is safer to start in Audit mode to understand the blast radius, then switch to Deny only after the impact is well understood.

Integrating ARM templates or Bicep files with Azure DevOps pipelines ensures every change is recorded in Git history, and running the same template repeatedly always converges to the same state (idempotency). Azure Blueprints is currently deprecated, so avoid it for new projects.

Reserved Instances are supported not just for VMs but also for Azure SQL Database, App Service, Cosmos DB, and many other services. When instance flexibility is enabled, the reservation discount automatically applies even if you change the size

Back to blog list