As part of a governance design, you plan to use Azure Policy across a large environment with many subscriptions. To which three scopes can you assign Azure Policy definitions? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: subscriptions, resource groups, management groups.
Why this is the answer
Azure Policy definitions can be assigned at three primary scopes to enforce governance across your Azure environment. Management groups provide a hierarchical structure above subscriptions, allowing you to apply policies to multiple subscriptions simultaneously. Subscriptions are a fundamental billing and management unit, and policies can be assigned directly to them. Resource groups are logical containers for Azure resources, enabling policy assignments to a specific set of resources within a subscription. Azure Active Directory (Azure AD) tenants are too broad and are not a direct scope for Azure Policy assignments. Azure AD administrative units are used for delegated administration within Azure AD and are not a scope for Azure Policy. Compute resources are too granular; policies are applied at a higher level, like resource groups, which then affect the resources within them.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed