Management groups
A management group is a container above Azure subscriptions: a policy or role assigned to it applies to every subscription beneath it. The Azure Enterprise Baseline builds a three-group tree under the tenant's root and assigns every guardrail at its top, so no subscription Owner can remove one.
What it does
Every Microsoft Entra tenant has one Tenant Root Group. Below it, management groups nest up to six levels deep, and each subscription sits in exactly one of them. Azure Policy assignments and Azure role assignments made at a management group are inherited by every child group, subscription, resource group and resource. An assignment at a lower scope can add access but cannot remove what is inherited, and a deny effect from a policy above wins over any role below.
How BuiltForProd uses it
The organizations unit (environments/core/root/global) creates the tree in modules/organizations/main.tf:
acme-core-root, the management subscription that holds the state backend, sits directly under mg-acme, outside the core and plat groups. The other nine core subscriptions (audit, security, identity, network, dns, artifacts, auto, corp, public) go under mg-acme-core, and the four stage subscriptions under mg-acme-plat. The subscriptions page lists what each one is for.
Everything preventive is assigned at mg-acme, the top of the tree:
| Assignment | What it holds | Source |
|---|---|---|
acme-sec-guard | The security guardrails initiative: seven Deny and three Audit built-ins, plus a custom deny of user role grants | policies-guardrails.tf |
acme-regions | The region restriction initiative | policies-guardrails.tf |
acme-audit-prot | The audit protection initiative with DenyAction effects | policies-guardrails.tf |
acme-tags | The tag policy: required values, Audit by default | policies-tags.tf |
acme-soc2-base, acme-mcsb… | The compliance initiatives switched on in security.hcl | modules/policy-compliance |
Assignment names stay within the 24 characters Azure allows at management-group scope. The region list (allowed_locations) is not typed by hand: the unit derives it from the home region, every region folder under environments/, and global, so adding a region folder also opens that region. Azure Policy describes each initiative.
People are granted access at the same scopes wherever possible. Platform Leads hold Owner and Security Admin at mg-acme, and DevOps Leads hold Owner at mg-acme-plat. When Privileged Identity Management is on, these become eligible assignments instead, the DevOps Leads' Owner then on each stage subscription. Platform Engineers hold Contributor and the DevOps groups the read-only role set at mg-acme-core, and both auditor groups hold Security Reader and the custom acme-security-auditor role at mg-acme. Stage access is granted per subscription, as Azure RBAC shows.
Terms you will see
| Term | Meaning |
|---|---|
| Tenant Root Group | The management group Azure creates for every tenant; the Baseline builds below it. |
mg-acme | The Baseline's top management group, where every guardrail is assigned. |
mg-acme-core | The group of the shared, single-purpose core subscriptions. |
mg-acme-plat | The group of the four stage subscriptions the blueprints deploy into. |
| Inheritance | Policy and role assignments flowing from a management group to everything beneath it. |
| Scope | The level an assignment is made at: management group, subscription, group or resource. |
Where to read more
- Azure Enterprise Baseline overview for the whole tree and its subscriptions.
- Landing zones for why the foundation is split into isolated units.
- Azure Policy for the initiatives assigned at
mg-acme.