<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="https://publishpress.com/"
	>

<channel>
	<title>azure governance Archives - Anuj Varma, Hands-On Technology Architect, Clean Air Activist</title>
	<atom:link href="https://www.anujvarma.com/tag/azure-governance/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.anujvarma.com/tag/azure-governance/</link>
	<description>Production Grade Technical Solutions &#124; Data Encryption and Public Cloud Expert</description>
	<lastBuildDate>Tue, 20 Jul 2021 14:21:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://www.anujvarma.com/wp-content/uploads/anujtech.png</url>
	<title>azure governance Archives - Anuj Varma, Hands-On Technology Architect, Clean Air Activist</title>
	<link>https://www.anujvarma.com/tag/azure-governance/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Azure Management Groups are tied to Governance</title>
		<link>https://www.anujvarma.com/azure-management-groups-are-tied-to-governance/</link>
					<comments>https://www.anujvarma.com/azure-management-groups-are-tied-to-governance/#respond</comments>
		
		<dc:creator><![CDATA[Anuj Varma]]></dc:creator>
		<pubDate>Wed, 17 Jun 2020 15:17:05 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[azure governance]]></category>
		<category><![CDATA[Azure Management Groups]]></category>
		<category><![CDATA[azure policies and management groups]]></category>
		<guid isPermaLink="false">https://googlearchitect.com/?p=215</guid>

					<description><![CDATA[<p>Also read this post on the core elements of Governance on any public cloud Why do we need Azure Management Groups? Most people think of management groups as a convenient [&#8230;]</p>
<p>The post <a href="https://www.anujvarma.com/azure-management-groups-are-tied-to-governance/">Azure Management Groups are tied to Governance</a> appeared first on <a href="https://www.anujvarma.com">Anuj Varma, Hands-On Technology Architect, Clean Air Activist</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Also read this post on the core elements of <a href="https://googlearchitect.com/?p=212&amp;preview=true">Governance on any public cloud</a></p>
<h3>Why do we need Azure Management Groups?</h3>
<p>Most people think of management groups as a convenient way to organize multiple subscriptions (e.g. based on departments in an organization).</p>
<p>However, management groups are tied to governance in that policies and RBAC can both be applied at a higher level &#8211; and propagate to all child subscriptions underneath.</p>
<p><strong>Per Department Management Groups</strong></p>
<p>You can have a high level Management group per department.</p>
<p><strong>What lives below a Management Group? (subscriptions and resource groups)</strong></p>
<p>Firstly, you get a root management group whether you ask for it or not (with each new subscription). So &#8211; it is best to group new subscriptions under existing roots so you have a clean hierarchy.</p>
<div class="section" lang="en" xml:lang="en">
<div class="titlepage">
<div>
<div>
<h4 class="title">Example Policy at Management Group Level &#8211; Tags of resources and Resource <mark data-markjs="true">Groups</mark></h4>
</div>
</div>
</div>
<p>Every resource in Azure including the resource <mark data-markjs="true">groups</mark> will mandatorily have tags assigned to it. The tags will include details about the department, environment, creation data, and project name at minimum.</p>
</div>
<div class="section" lang="en" xml:lang="en">
<div class="titlepage">
<div>
<div>
<h4 class="title">Another Example Policy at the management group level  &#8211; Diagnostic logs and Application Insights for all resources</h4>
</div>
</div>
</div>
<p>Every resource deployed on Azure should have diagnostic logs and application logs enabled wherever possible.</p>
<p><strong>How many Subscriptions should you have?</strong></p>
<p>At the very least, 2 (one for production and one for non production workloads). Beyond PROD and NON PROD, you can consider departmental based subscriptions (if Billing is to be separated).. Read Azure&#8217;s <a href="https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/ready/azure-best-practices/organize-subscriptions">Article on Subscription Groups</a></p>
</div>
<h3>Summary</h3>
<p>Azure Management Groups are more than a convenience for organizing subscriptions. Used correctly, they allow policies to be applied in a reusable manner. For example, they can be used to enforce tagging of resources, a key part of cost governance.</p>
<p>Also see <a href="https://googlearchitect.com/2020/06/12/security-audits-on-aws-accounts/">Auditing AWS Account Security</a>.</p>
<p><a href="https://calendly.com/anujvarma/private-1-on-1-conversation">Set up a 1 on 1 appointment with Anuj to assist with your cloud journey</a></p>
<p>The post <a href="https://www.anujvarma.com/azure-management-groups-are-tied-to-governance/">Azure Management Groups are tied to Governance</a> appeared first on <a href="https://www.anujvarma.com">Anuj Varma, Hands-On Technology Architect, Clean Air Activist</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.anujvarma.com/azure-management-groups-are-tied-to-governance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Azure Governance</title>
		<link>https://www.anujvarma.com/azure-governance/</link>
					<comments>https://www.anujvarma.com/azure-governance/#respond</comments>
		
		<dc:creator><![CDATA[Anuj Varma]]></dc:creator>
		<pubDate>Tue, 22 Jan 2019 04:12:00 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[azure governance]]></category>
		<guid isPermaLink="false">http://www.anujvarma.com/?p=5574</guid>

					<description><![CDATA[<p>Azure&#8217;s Governance Toolkit is very different from AWS&#8217;s &#8211; although they try to accomplish a lot of the same things. At a high level, this is Azure&#8217;s breakdown of services/techniques [&#8230;]</p>
<p>The post <a href="https://www.anujvarma.com/azure-governance/">Azure Governance</a> appeared first on <a href="https://www.anujvarma.com">Anuj Varma, Hands-On Technology Architect, Clean Air Activist</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Azure&#8217;s Governance Toolkit is very different from AWS&#8217;s &#8211; although they try to accomplish a lot of the same things. At a high level, this is Azure&#8217;s breakdown of services/techniques for better cost and resource governance.</p>
<p>&#8212; Management Groups &#8211;&nbsp; grouping and organizing your subscriptions in a logical hierarchy</p>
<p>&#8212; Resource Graphs &#8211; These help query complex aspects of azure resources (how many VMs have managed disks attached&#8230;?)</p>
<p>&#8212; Policies &#8211; Similar to AWS policies.</p>
<p>&#8212; Blueprints (resource groups, policies, role assignments, Resource Manager templates ) &#8211; Close to AWS CloudFormation Templates</p>
<h3>Sample Governance Probing Questions and Answers (for Azure)</h3>
<h4>Do you need to manage multiple accounts and subscriptions?</h4>
<ul>
<li>Use Azure Management Groups to create an organizational hierarchy so that access control policies can be inherited.</li>
</ul>
<h4>Are you using RBAC? Are you leveraging Azure Policy?</h4>
<ul>
<li>&nbsp; On RBAC,&nbsp; use Azure Policy and possibly define programmatic ways (using Azure Powershell or CLI) to apply control policies.</li>
</ul>
<h4>Are you using Tagging Effectively? How about Centralized Logging?</h4>
<ul>
<li>Create a tagging policy that accounts for cost centers, development environments as well as departmental units.</li>
<li>Collect and store logs for all Azure Subscriptions, accounts, resource groups, resources and Azure REST API actions</li>
</ul>
<h4>How are you currently enforcing Security Compliance?</h4>
<ul>
<li>Try scheduling continuous monitoring tasks (for example, vulnerability scans within and across subscriptions)</li>
</ul>
<h4>How are you enforcing Cost and Budget compliance?</h4>
<ul>
<li>Set rules to define enforcement actions (including notification and block creation of new cloud resources) when compliance thresholds are exceeded. Cloudcheckr and related tools may help define such rules, but it cloud be done cloud native as well.</li>
</ul>
<h3>What access is needed on an existing subscription? </h3>
<p>The Azure Global Admin needs to create a Service Principal within the subscription, with Reader rights</p>
<p>(Optional) CloudCheckr Deployment&nbsp; within the Azure Tenant(s)</p>
<ul>
</ul>
<p>The post <a href="https://www.anujvarma.com/azure-governance/">Azure Governance</a> appeared first on <a href="https://www.anujvarma.com">Anuj Varma, Hands-On Technology Architect, Clean Air Activist</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.anujvarma.com/azure-governance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Content Delivery Network via N/A
Minified using Disk

Served from: www.anujvarma.com @ 2026-07-22 12:29:51 by W3 Total Cache
-->