πŸ—οΈ Designing Management Group Hierarchy

Where Governance Actually Starts

Most people think Management Groups are just:

β€œfolders to organize subscriptions”

That thinking is wrong.


πŸ”₯ What Management Groups Really Are

Management Groups define governance boundaries β€” not structure for convenience

They control:


❌ The Wrong Way to Design MGs

1. Designing based on teams

1) Finance
2) HR
3) Retail Banking 4) etc..

πŸ‘‰ Problem:


2. Designing based on applications

App1
App2
App3

πŸ‘‰ Problem:


βœ… The Right Way

Design based on:

Control boundaries that will remain stable over time


🧠 The 3 Core Dimensions You Must Think In

Before drawing anything, answer:


1. Governance & Policy Boundaries

Example:


2. Platform vs Workloads

Separate:

πŸ‘‰ This is non-negotiable in enterprise design


3. Lifecycle & Risk Segmentation


🏦 Realistic Enterprise Structure

Here’s a practical starting point:

Tenant Root  
β”‚  
β”œβ”€β”€ Platform  
β”‚   β”œβ”€β”€ Identity  
β”‚   β”œβ”€β”€ Connectivity  
β”‚   └── Management-Security  
β”‚  
β”œβ”€β”€ Landing Zones  
β”‚   β”œβ”€β”€ Regulated  
β”‚   β”‚   β”œβ”€β”€ PCI  
β”‚   β”‚   β”œβ”€β”€ GDPR  
β”‚   β”‚   └── Core-Banking  
β”‚   β”‚  
β”‚   β”œβ”€β”€ Non-Regulated  
β”‚   β”‚   β”œβ”€β”€ Production  
β”‚   β”‚   └── Non-Production  
β”‚   β”‚  
β”‚   └── Sandbox  
β”‚  
β”œβ”€β”€ Transitional  
β”‚   β”œβ”€β”€ Quarantine  
β”‚   └── Decommissioning

πŸ” Why This Structure Works

Platform is isolated


Landing Zones are structured by risk


Sandbox is isolated


Transitional zones exist


⚠️ Key Design Decisions You Must Make

Decision 1: Where do policies differ?

πŸ‘‰ This defines your MG split

Decision 2: What is centrally controlled?

πŸ‘‰ Platform vs workload separation

Decision 3: Where do you expect exceptions?

πŸ‘‰ Plan for:


πŸ”₯ Real-World Mistake

Most teams do this:

β€œLet’s copy Microsoft’s reference architecture exactly”

Problem:


🧠 Architect Thinking

You don’t ask:

β€œWhat is the correct MG structure?”

You ask:

β€œWhere do I need different control behavior?”


πŸ” Example (Important)

If PCI needs:

πŸ‘‰ It must be a separate MG


If Dev vs Prod:

πŸ‘‰ Don’t create MG β€” use subscription/RBAC


πŸ’‘ One-Line Rule

Create a new Management Group only when policy or governance needs to change significantly


Where Most People Go Wrong

Now that MG structure is clear, the next logical step is:

πŸ‘‰ Subscription Design Strategy

Because:

MG defines governance
Subscription defines ownership, cost, and deployment boundary


β¬… Back to Series Home β¬… Back to: Why Landing Zones Fail Next: Subscription Design ➑