Chapter 3: Governance and Compliance Flashcards
What is a Subscription?
Billing unit that aggregates all costs of underlying resources
Helps segment billing units into logical ownership
Ex. Marketing vs. Engineering
What does a subscription contain?
Contain resource groups and associated resources
Each resource group must be part of one single subscription
Subscription is a scoping level for deploying ARM templates
What are some types of subscriptions?
Pay as you Go
Free Trial
Enterprise Agreement
What are 3 major types of subscription naming conventions?
Environment - Prod, Dev, Staging
Department/Teams
Region - geographical region of the business
What is a Management Group?
Container to manage subscriptions in a parent/child relationship
What is the Root Management Group?
Top level management group - cannot put another manage group above
How many levels of management groups can you have?
6 levels
Can you deploy an Azure Policy at the Management Group level?
Yes
Can you deploy RBAC at the Management Group level?
Yes
Why is it important to understand where you set scope for RBAC and Policies?
The level of scope will allow those settings to flow down from there - cascade downward
Are users given access to a root management group by default?
No, this would allow users highest scope control
Only the global admin
Can Root Management Groups be moved or deleted?
No
What can the global admin do in the event of getting locked out?
Global Administrators can elevate themselves to User Access Admin of root group
What is an Azure Policy?
Enforce compliance and enable auditing
You determine what is “compliant”
What are some use cases for policies?
Prohibiting services and/or resources to control costs
Enforce allowed locations