Management Groups and Landing Zone Governance (Scenario)
A scenario-driven governance lab. Management groups are tenant-scoped shared objects, so instead of creating them live in the shared lab tenant you design the hierarchy, author and analyze policy-initiative and RBAC-inheritance JSON, apply governance tags live (Contributor-safe), and author a CanNotDelete lock plan (creating locks needs Owner or User Access Administrator).
Lab Overview
Practice the management group, subscription, policy, and RBAC governance reasoning that AZ-104 expects, within the permission limits of a Contributor, subscription-scoped service principal.
Management groups are tenant-scoped objects shared across the whole directory. Creating them live is either blocked by the tenant's hierarchy protection or would pollute the shared lab tenant with management groups no cleanup script can remove, so this lab keeps management group design as artifacts. This is a rigorous artifact-and-reasoning lab. You inspect a realistic static governance landscape, design a target management group hierarchy, map how a policy initiative and inherited RBAC flow down the tree, and produce a landing-zone governance decision document.
One task is fully live and Contributor-safe: you create a real resource group, apply governance tags, and confirm them with the Azure CLI and portal. Creating a management lock needs Owner or User Access Administrator (Microsoft.Authorization/locks/write is denied to Contributor), so you author a CanNotDelete lock plan instead. Every other task validates the structure and content of the governance artifacts you author, not live management group creation.
What You'll Learn
Inspect an existing governance landscape with read-only Azure CLI and static artifacts
Design a target management group hierarchy that follows Cloud Adoption Framework landing-zone patterns
Map how an Azure Policy initiative and inherited RBAC assignments flow down a management group tree
Apply governance tags live to a real resource group (Contributor-safe) and author a CanNotDelete lock plan
Author a landing-zone governance decision document that justifies hierarchy, policy, and RBAC choices
Prerequisites
Basic command line familiarity
Basic understanding of Azure subscriptions and resource groups
Basic understanding of Azure RBAC role assignments
Comfort reading and editing JSON
Technologies Covered
Part of a Course
This lab is part of the Microsoft Azure Administrator (AZ-104) course
View All CoursesChoose your plan
Simple, Transparent Pricing
Unlock full access to TeKanAid courses, labs, and bootcamps
Just exploring? Start free below. Want the full experience? Try Premium free for 7 days (card required, $0 today).
Pro
All courses, with lab scripts to run on your own machine
Renews automatically. Cancel anytime.
Final price verified at checkout.
- Full access to all courses
- Lab scripts to download and run on your own machine (hosted labs not included)
- Progress tracking
- Certificate of completion
- Community access
- Bootcamp participation
- New content access
Premium
Full access, including unlimited hosted labs
Renews automatically. Cancel anytime.
Final price verified at checkout.
- Everything in Pro
- Unlimited hands-on labs, fully hosted on TeKanAid Academy (nothing to set up)
- Lab AI Assistant
- Accelerator bootcamps with live office hours
- Priority support
Prefer a single course?
Purchase individual courses for a one-time fee of $79. Full access to course content, quizzes, certificates, and community features, lab access is not included.
Browse CoursesJust exploring? Start free, no account needed
Three free ways to start. All bridge into the paid Premium catalog when you're ready.
Not ready to commit? The crash course is email-only. No academy account required.
Ready to Get Started?
Start this hands-on lab and build real-world Platform Engineering skills
Get Access Now