# Land new Azure subscriptions in an explicit default management group

> Review the hierarchy's default landing group and its inherited controls before onboarding another subscription.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-175-land-new-azure-subscriptions-in-an-explicit-default-management-group/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:01+00:00
- Modified: 2026-09-10T00:55:36+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Review the hierarchy's default landing group and its inherited controls before onboarding another subscription.

## Potentially affected

Azure tenants configuring management-group hierarchy settings for new subscriptions.

## DSE recommendation

Define and test the default management-group landing zone with approved policy and role inheritance.

## Article

## Source facts

A newly added subscription normally joins the tenant’s root management group. Policy and role assignments at that root immediately affect the new subscription. Microsoft provides a hierarchy setting to select a different default management group for new subscriptions.

That lets an organization retain root-level governance while placing additional controls appropriate to new subscriptions on a separate landing group. Permissions to read and update hierarchy settings do not themselves grant other access throughout the hierarchy. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/governance/management-groups/how-to/protect-resource-hierarchy).

## Applicability

Identify the tenant root, current default group, proposed landing group, and inherited assignments. Keep the authority to change the hierarchy setting separate from the service owner’s permissions inside an individual subscription.

## DSE recommendation

DSE recommends treating the default group as an onboarding control. Have platform and security owners approve its intended policies and access, then document the process for moving a subscription onward after onboarding. Preserve the old setting and review existing automation that assumes every new subscription initially appears under the root.

## Verification

Using an approved test onboarding, inspect the subscription’s actual parent and effective governance. Confirm that intended controls apply and required onboarding work remains possible. Record the hierarchy setting, resulting placement, and any exceptions. Recheck this path after hierarchy or landing-group assignment changes rather than relying on the configured name alone.

## Official references

[Microsoft Learn: Protect your resource hierarchy – Azure Governance](https://learn.microsoft.com/en-us/azure/governance/management-groups/how-to/protect-resource-hierarchy). Source retrieved September 9, 2026.

## Primary reference

- Name: Protect your resource hierarchy - Azure Governance - Azure governance | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/governance/management-groups/how-to/protect-resource-hierarchy
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Land new Azure subscriptions in an explicit default management group,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-175-land-new-azure-subscriptions-in-an-explicit-default-management-group/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
