Microsoft Azure

Governance & Security — Management Groups, Policy & Defender

Organise subscriptions, set guardrails nobody can escape, and detect what RBAC cannot prevent.

Governance sits above individual resources, in a hierarchy that inherits downward.

Site rules for a campus of buildings. They apply to everyone including the site manager, access badges are separate per building, and cameras record what the rules did not anticipate.

Key Concepts

1
    Management Group (root)
      +-- Platform MG        connectivity, identity, management
      +-- Landing Zones MG
      |     +-- Corp         subscriptions for internal workloads
      |     +-- Online       subscriptions for internet-facing
      +-- Sandbox MG         experiments, capped spend
2
RBAC and Policy inherit down this tree, so a role or rule set at a management group applies to every subscription beneath it.
3
Separate subscriptions are the practical blast radius boundary — separate quotas, separate billing, and a mistake in development cannot touch production resources.
4
Azure Policy is the guardrail, and it is not RBAC.
    RBAC    who may perform an action
    Policy  what the resource is ALLOWED TO LOOK LIKE
5
So an Owner can still be refused. Typical policies: deny public IPs on VMs, deny storage accounts without HTTPS-only, require tags, restrict regions, enforce allowed SKUs.
6
Effects are the part to know.
    Deny            block the request
    Audit           record non-compliance, allow it
    DeployIfNotExists  remediate automatically
    Modify          add or change properties, such as tags
7
Start in Audit. A Deny policy applied straight to a live estate blocks legitimate deployments and gets governance a bad name.
8
DeployIfNotExists is the one that does real work — switching on diagnostic settings everywhere, for instance, rather than asking teams to remember.
DeployIfNotExists
9
Initiatives group policies into a set you assign once, which is how regulatory baselines are applied.
10
Microsoft Defender for Cloud scores and detects. Secure Score ranks what to fix; the plans add threat detection for VMs, storage, SQL and containers. Sentinel is the SIEM above it for correlation and hunting.
11
Locks prevent accidents. CanNotDelete and ReadOnly on a resource group, which is the simplest protection against the most realistic disaster.
CanNotDeleteReadOnly
12
Root accounts and standing admin. Use Privileged Identity Management so administrative roles are activated just in time and expire, rather than being held permanently.
13
What the interviewer is probing.1. "What is the difference between RBAC and Azure Policy?" Probing: the two controls. Stalls: "Both control access." Moves up: RBAC decides who may act; Policy decides what the resource is allowed to look like — so an Owner can still be refused.
14
2. "How do you roll out a Deny policy safely?" Probing: the sequencing. Stalls: "Apply it." Moves up: start in Audit to see what it would block, fix the violations, then switch to Deny — otherwise it blocks legitimate deployments.
15
3. "What does DeployIfNotExists do?" Probing: the remediation effect. Stalls: "It reports problems." Moves up: it remediates — switching on diagnostic settings across the estate rather than asking teams to remember.
16
4. "Why separate subscriptions per environment?" Probing: blast radius. Stalls: "For billing." Moves up: separate quotas, billing and a hard boundary, so a mistake in development cannot touch production.