Land new Azure subscriptions in an explicit default management group

Review the hierarchy's default landing group and its inherited controls before onboarding another subscription.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Review the hierarchy's default landing group and its inherited controls before onboarding another subscription.

Potentially affected

Azure tenants configuring management-group hierarchy settings for new subscriptions.

DSE recommendation

Define and test the default management-group landing zone with approved policy and role inheritance.

Source facts

A newly added subscription normally joins the tenant’s root management group. Policy and role assignments at that root immediately affect the new subscription. Microsoft provides a hierarchy setting to select a different default management group for new subscriptions.

That lets an organization retain root-level governance while placing additional controls appropriate to new subscriptions on a separate landing group. Permissions to read and update hierarchy settings do not themselves grant other access throughout the hierarchy. Microsoft Learn.

Applicability

Identify the tenant root, current default group, proposed landing group, and inherited assignments. Keep the authority to change the hierarchy setting separate from the service owner’s permissions inside an individual subscription.

DSE recommendation

DSE recommends treating the default group as an onboarding control. Have platform and security owners approve its intended policies and access, then document the process for moving a subscription onward after onboarding. Preserve the old setting and review existing automation that assumes every new subscription initially appears under the root.

Verification

Using an approved test onboarding, inspect the subscription’s actual parent and effective governance. Confirm that intended controls apply and required onboarding work remains possible. Record the hierarchy setting, resulting placement, and any exceptions. Recheck this path after hierarchy or landing-group assignment changes rather than relying on the configured name alone.

Official references

Microsoft Learn: Protect your resource hierarchy – Azure Governance. Source retrieved September 9, 2026.

Primary reference

Review the official source

Protect your resource hierarchy - Azure Governance - Azure governance | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE