Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 2 question 57 discussion

Actual exam question from Microsoft's AZ-104
Question #: 57
Topic #: 2
[All AZ-104 Questions]

HOTSPOT -
You have an Azure subscription that contains the hierarchy shown in the following exhibit.

You create an Azure Policy definition named Policy1.
To which Azure resources can you assign Policy1 and which Azure resources can you specify as exclusions from Policy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Tenant Root Group, ManagementGroup1, Subscription1, RG1, and VM1
Once your business rules have been formed, the policy definition or initiative is assigned to any scope of resources that Azure supports, such as management groups, subscriptions, resource groups, or individual resources.
Note: Azure provides four levels of scope: management groups, subscriptions, resource groups, and resources. The following image shows an example of these layers.

Box 2: ManagementGroup1, Subscription1, RG1, and VM1
You can exclude a subscope from the assignment.
Reference:
https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/overview

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Ntinsky
Highly Voted 2 years ago
Since the discussion added a lot of confusion cause a lot of people in here just drop random facts without any proof,misleading people, i tested it at an Azure lab. In the scope field at the "Basics" tab i was able to select "Tenant Root Group" or "Management Group1" with the optional entries of Subscription and Resource group So ""you can assign policy to Tenant Root Group,ManagementGroup1,Subscription1 and RG1"" As for the second answer about the exclusions, i was able to select all the items in the scope EXCEPT the Tenant Root Group Therefore the correct answer would be ""ManagementGroup1,Subscription1,RG11 and VM1"" I hope that helps
upvoted 249 times
Sanaz90
2 months, 2 weeks ago
Wrong! Go to a resource like vm and assign a policy from there to vm and you will see the policy assignment is set to resource level and not rg level
upvoted 1 times
...
codeScalable
1 year, 10 months ago
azure policies can be scoped down to individual resources. "Once your business rules have been formed, the policy definition or initiative is assigned to any scope of resources that Azure supports, such as management groups, subscriptions, resource groups, or individual resources." the second answer is correct
upvoted 11 times
...
AK4U_111
1 year, 7 months ago
for the exclusions, the Subscription dropdown menu is grayed out as well as the Resource Group drop down menu.
upvoted 1 times
...
gpCert
1 year, 8 months ago
Why you could not assign policy to VM1 (for the first answer?)
upvoted 5 times
...
...
RichardBill
Highly Voted 2 years, 1 month ago
Wrong! You can assign a policy to the Root, Management Group, Subscription and Ressource Group BUT NOT A RESSOUCE ITSELF! Test it in Portal! 2nd part of answer seems to be correct. You can not Exclude the highest scope that you can assign to. I tried it in portal as well and it wont save the exclusion Tenant Root Group
upvoted 35 times
Traian
2 years, 1 month ago
I believe you are wrong. You can assign a policy to a resource :"An assignment is a policy definition or initiative that has been assigned to a specific scope. This scope could range from a management group to an individual resource." https://docs.microsoft.com/en-us/azure/governance/policy/overview - check assignments In my opinion the provided answer is correct
upvoted 23 times
RichardBill
2 years, 1 month ago
So I checked again and the portal doesnt let you do it! Thats what I based my assumption! But via Azure CLI it says that a ressource is a vaild scope for assignment: https://docs.microsoft.com/en-us/cli/azure/policy/assignment?view=azure-cli-latest#az-policy-assignment-create So yeah I think that you are right and my comment is wrong but I can not delete it. But looks like this is just a portal restriction. Sorry for the confusion!
upvoted 35 times
meeko86
1 year, 11 months ago
Valid scopes are management group, subscription, resource group, and resource https://learn.microsoft.com/en-us/cli/azure/policy/assignment?view=azure-cli-latest#az-policy-assignment-create
upvoted 4 times
...
...
...
Grande
2 years, 1 month ago
very correct. in general you cannot exclude the parent of a child already covered by the policy e.g. if scope was RG1, you cannot exclude Subs1, you can only exclude resources underneath RG1
upvoted 1 times
...
northstar88
2 years, 1 month ago
Tried in portal as well. You cannot select resources as scope.
upvoted 4 times
...
buzzerboy
1 year, 9 months ago
I couldnt assign a policy at Tenant Root Management Group. There is no blade for policy.
upvoted 2 times
...
...
fittech
Most Recent 3 days, 3 hours ago
!! Please be careful not to share incorrect information! According to Microsoft documentation: "policies can be assigned to any scope of resources that Azure supports, such as management groups, subscriptions, resource groups, or individual resources." !! -
upvoted 1 times
...
SeMo0o0o0o
3 weeks, 3 days ago
WRONG You can assign Policy1 to: Tenant Root Group, ManagementGroup1, Subscription1, and RG1 only You can exclude Policy1 from: ManagementGroup1, Subscription1, RG1, and VM1 only
upvoted 1 times
...
SeMo0o0o0o
1 month ago
Wrong You can assign Policy1 to: Tenant Root Group, ManagementGroup1, and Subscription1 only You can exclude Policy1 from: ManagementGroup1, Subscription1, RG1, and VM1 only
upvoted 1 times
SeMo0o0o0o
3 weeks, 3 days ago
sorry i misserad it, You can assign Policy1 to: Tenant Root Group, ManagementGroup1, Subscription1, and RG1 only You can exclude Policy1 from: ManagementGroup1, Subscription1, RG1, and VM1 only
upvoted 1 times
...
Mshaty
3 weeks, 5 days ago
if you can exclude it doesnt that mean you can assign the policy to the resource ?you cant exclude something that cannot be part of the policy
upvoted 1 times
SeMo0o0o0o
3 weeks, 3 days ago
you can´t assign a policy for a resource on the portal, you can do it only on CLI or PowerShell, which is not mintioned here, so we have to answer this in gerenal.
upvoted 1 times
...
...
...
pasangawa
1 month ago
tested on lab, you can assign policy on vm
upvoted 1 times
...
pet3r
2 months, 2 weeks ago
Policies can be applied to the resource like VM https://learn.microsoft.com/en-us/azure/governance/policy/concepts/recommended-policies
upvoted 1 times
...
VinodRK
3 months, 1 week ago
You can assign Policy1 to Tenant Root Group, ManagementGroup1, Subscription1, and RG1 only You can exclude Policy1 from ManagementGroup1, Subscription1, RG1, and VM1 only
upvoted 1 times
...
23169fd
3 months, 3 weeks ago
given answer is correct.
upvoted 2 times
...
76d5e04
4 months ago
Feeling tired of reading discussions. examtopics please quality seems ?
upvoted 2 times
...
76d5e04
4 months ago
In the name of discussion most confusion is created and makes me think is it worth paying $65 to examtopics. I thought examtopics would be a good material so far out of 90 questions most of them have not been given exact answer
upvoted 1 times
nailedIT
2 months ago
The issue lies on the people and bots using examtopics. I still find it very useful to get access to the questions, but I can never rely exclusively on examtopics answers nor community. Yet, community seems to be sharp on the right answer than examtopics, but is full of bots giving almost random answers without any explanation.
upvoted 1 times
...
...
Limobakry
4 months, 3 weeks ago
the key in question is only
upvoted 1 times
...
3c5adce
4 months, 4 weeks ago
You can Assign policy to: Tenant Root Group, ManagementGroup1, Subscription1 and RG1 ONLY" You can Exclude policy from: ""ManagementGroup1,Subscription1,RG1, and VM1 ONLY""
upvoted 1 times
...
MCLC2021
5 months ago
1/ You can assing Policy1 to: Tenant Root Group, Mangement Group 1, Subscription 1, RG1,VM1 2/ You can exclude Policy1 to: Mangement Group 1, Subscription 1,RG1,VM1 "Once your business rules have been formed, the policy definition or initiative is assigned to any scope of resources that Azure supports, such as management groups, subscriptions, resource groups, or individual resources." https://learn.microsoft.com/en-us/azure/governance/policy/overview "Subscopes can be excluded, if necessary. "https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/overview#understand-scope
upvoted 1 times
Dankho
1 week, 5 days ago
Link doesn't include tenant level.
upvoted 1 times
...
...
op22233
5 months, 1 week ago
The given answers are correct. Policy can be applied to all, Remember the kind of policy you can apply to prevent a particular set of types of instance while creating your VM. , then the Only you can exclude all except the Tenant root Group from a policy.
upvoted 2 times
...
WeepingMaplte
5 months, 3 weeks ago
Answer should be: 1) Tenant Root Group, MG1, Sub1 and RG1 Only 2) MG1, Sub1, RG1 and VM1 only
upvoted 2 times
...
Amir1909
7 months, 3 weeks ago
Assign policy1: 4te Antwort Eclude policy1: 4te Antwort
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...