Subscriptions
An Azure subscription is the boundary for billing, quotas and role assignments: what happens in one subscription cannot spend, exhaust or grant access in another. The Azure Enterprise Baseline runs on 14 subscriptions, each with one job, and every one of them receives the same subscription baseline.
What it does
Every Azure resource lives in a resource group, and every resource group in one subscription. A subscription has its own invoice lines, its own service limits and its own role assignments, and sits under one management group, from which it inherits policy and access. Subscriptions are created against a billing scope (an Enterprise Agreement enrollment account, a Microsoft Customer Agreement invoice section or a partner customer) through a subscription alias, or created by hand and then managed. Before a subscription can create resources of a type, the matching resource provider, such as Microsoft.ContainerService, must be registered in it.
How BuiltForProd uses it
The organizations unit creates or adopts the subscriptions in modules/organizations/subscriptions.tf. Every name listed in subscription_ids is an existing subscription the code adopts and never creates; every other name is created with an alias when billing_scope_id is set. The two sources combine, so some subscriptions can be adopted and the rest created. Each one is then placed under its management group.
| Subscription | Management group | Job |
|---|---|---|
acme-core-root | mg-acme | Management subscription: the state backend and the tenant-level units |
acme-core-audit | mg-acme-core | Audit Log Analytics workspace and the immutable audit storage |
acme-core-security | mg-acme-core | Security workspace, action group, SOPS keys, secrets syncer, DDoS plan |
acme-core-identity | mg-acme-core | Entra groups and role assignments, PIM, Conditional Access |
acme-core-network | mg-acme-core | Hub virtual network, firewall, private DNS, DNS resolver |
acme-core-dns | mg-acme-core | Public DNS zones and DNSSEC |
acme-core-artifacts | mg-acme-core | Container registry, shared storage, Unity Catalog metastore root |
acme-core-auto | mg-acme-core | GitHub federated identities, the CI platform vault, Container Apps runners |
acme-core-corp | mg-acme-core | Reserved; receives the baseline only |
acme-core-public | mg-acme-core | Intentionally public assets |
acme-plat-sandbox, -dev, -staging, -prod | mg-acme-plat | One subscription per stage, identical in shape; the blueprints deploy here |
After every change, the unit writes org_subscriptions.hcl at the repository root: the tenant, management-group and subscription IDs, and no secret. root.hcl reads that file to point each unit's provider and backend at the subscription its folder names, so a unit under environments/plat/prod/ always lands in acme-plat-prod without an ID in its configuration.
Every subscription runs the subscription-baseline unit (modules/subscription-baseline):
- Resource providers are registered explicitly from one list in the unit.
root.hclsetsresource_provider_registrations = "none", so the provider registers only the listed namespaces, waits until they are registered and never unregisters one. - Microsoft Defender for Cloud plans, each set to Standard or Free from
security.hcl, the security contact and the security workspace setting. - Activity Log export: a diagnostic setting sends eight Activity Log categories to the audit workspace and the immutable audit storage account in
acme-core-audit. - Network Watcher in
NetworkWatcherRG, created before any virtual network so Azure does not create its own. - A baseline resource group
<prefix>-baseline-rgwith aCanNotDeletelock.
The blueprints never create subscriptions. The Web App, Data and ETL, and Secrets blueprints deploy into acme-plat-dev, acme-plat-staging and acme-plat-prod, and read each stage's facts from its contract vault.
Terms you will see
| Term | Meaning |
|---|---|
| Billing scope | The Enterprise Agreement, Microsoft Customer Agreement or partner scope that pays. |
| Subscription alias | The resource that creates a subscription against a billing scope. |
| Adopted subscription | An existing subscription listed in subscription_ids, placed and baselined, never created. |
| Resource provider | The service namespace a subscription must register before it can create that type. |
org_subscriptions.hcl | The generated, committed file that maps subscription names to IDs for root.hcl. |
| Subscription baseline | The unit every subscription runs: providers, Defender, Activity Log, Network Watcher, lock. |
Where to read more
- Azure Enterprise Baseline overview for what each subscription holds.
- Azure Web App Blueprint overview, Data and ETL Blueprint overview and Secrets Blueprint overview for what lands in the stage subscriptions.
- Landing zones for why each job gets its own subscription.