Management Groups
- a hierarchy that can be created for better management of subscriptions
- All subscriptions under a management group inherit the conditions applied to the management group
- A management group can have 6 levels of depth. It does not include the root MG. root MG has the same ID as tenant AAD ID.
- by default all subscriptions get added to root MG.
- 1 MG can have only 1 parent, but multiple children
references:
Paths into this note
5 notes lead here
-
No lock at management group level
-
which is then assigned to a scope (subscription,resource groups,management group or resources)
-
Applies to all items in control plane (management groups,resource groups, resources)
-
At root management group level for example, you want broad policies that need to apply. Least restrictive. And so on.