Skip to main content

Subscriptions

An Azure subscription is the boundary for billing, quotas and role assignments: what happens in one subscription cannot spend, exhaust or grant access in another. The Azure Enterprise Baseline runs on 14 subscriptions, each with one job, and every one of them receives the same subscription baseline.

What it does​

Every Azure resource lives in a resource group, and every resource group in one subscription. A subscription has its own invoice lines, its own service limits and its own role assignments, and sits under one management group, from which it inherits policy and access. Subscriptions are created against a billing scope (an Enterprise Agreement enrollment account, a Microsoft Customer Agreement invoice section or a partner customer) through a subscription alias, or created by hand and then managed. Before a subscription can create resources of a type, the matching resource provider, such as Microsoft.ContainerService, must be registered in it.

How BuiltForProd uses it​

The organizations unit creates or adopts the subscriptions in modules/organizations/subscriptions.tf. Every name listed in subscription_ids is an existing subscription the code adopts and never creates; every other name is created with an alias when billing_scope_id is set. The two sources combine, so some subscriptions can be adopted and the rest created. Each one is then placed under its management group.

SubscriptionManagement groupJob
acme-core-rootmg-acmeManagement subscription: the state backend and the tenant-level units
acme-core-auditmg-acme-coreAudit Log Analytics workspace and the immutable audit storage
acme-core-securitymg-acme-coreSecurity workspace, action group, SOPS keys, secrets syncer, DDoS plan
acme-core-identitymg-acme-coreEntra groups and role assignments, PIM, Conditional Access
acme-core-networkmg-acme-coreHub virtual network, firewall, private DNS, DNS resolver
acme-core-dnsmg-acme-corePublic DNS zones and DNSSEC
acme-core-artifactsmg-acme-coreContainer registry, shared storage, Unity Catalog metastore root
acme-core-automg-acme-coreGitHub federated identities, the CI platform vault, Container Apps runners
acme-core-corpmg-acme-coreReserved; receives the baseline only
acme-core-publicmg-acme-coreIntentionally public assets
acme-plat-sandbox, -dev, -staging, -prodmg-acme-platOne subscription per stage, identical in shape; the blueprints deploy here

After every change, the unit writes org_subscriptions.hcl at the repository root: the tenant, management-group and subscription IDs, and no secret. root.hcl reads that file to point each unit's provider and backend at the subscription its folder names, so a unit under environments/plat/prod/ always lands in acme-plat-prod without an ID in its configuration.

Every subscription runs the subscription-baseline unit (modules/subscription-baseline):

  • Resource providers are registered explicitly from one list in the unit. root.hcl sets resource_provider_registrations = "none", so the provider registers only the listed namespaces, waits until they are registered and never unregisters one.
  • Microsoft Defender for Cloud plans, each set to Standard or Free from security.hcl, the security contact and the security workspace setting.
  • Activity Log export: a diagnostic setting sends eight Activity Log categories to the audit workspace and the immutable audit storage account in acme-core-audit.
  • Network Watcher in NetworkWatcherRG, created before any virtual network so Azure does not create its own.
  • A baseline resource group <prefix>-baseline-rg with a CanNotDelete lock.

The blueprints never create subscriptions. The Web App, Data and ETL, and Secrets blueprints deploy into acme-plat-dev, acme-plat-staging and acme-plat-prod, and read each stage's facts from its contract vault.

Terms you will see​

TermMeaning
Billing scopeThe Enterprise Agreement, Microsoft Customer Agreement or partner scope that pays.
Subscription aliasThe resource that creates a subscription against a billing scope.
Adopted subscriptionAn existing subscription listed in subscription_ids, placed and baselined, never created.
Resource providerThe service namespace a subscription must register before it can create that type.
org_subscriptions.hclThe generated, committed file that maps subscription names to IDs for root.hcl.
Subscription baselineThe unit every subscription runs: providers, Defender, Activity Log, Network Watcher, lock.

Where to read more​