AZIAM-008: Management group structure review

Platform
Entra ID / M365
Category
Azure IAM & Resource Security
Severity
Info
Zero Trust pillar
Identity (weight 2)
Golden fixtures
4
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Management groups provide a hierarchical structure for organizing subscriptions and applying governance controls at scale. A poorly designed or flat management group structure makes it difficult to enforce differentiated policies for production, development, and sandbox environments. Reviewing the hierarchy ensures that policy inheritance and role assignments align with organizational security requirements.

Recommended value

Implement a management group hierarchy that separates production, development, and sandbox environments with appropriate policy assignments

Remediation

Review the current management group hierarchy and ensure it reflects organizational boundaries such as business units, environments, and workload classifications. Apply restrictive policies at higher management group levels for broad enforcement and allow exceptions at lower levels only with documented justification. Ensure the root management group has minimal direct role assignments and that sensitive subscriptions are placed in appropriately governed management groups.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for AZIAM-008
ScenarioExpected verdict
cleanPASS
known-badWARN
no-dataNot Assessed
partial-collectionNot Assessed

Framework mappings

NIST SP 800-53
AC-2