What you need to know
Review the hierarchy's default landing group and its inherited controls before onboarding another subscription.
Potentially affected
Azure tenants configuring management-group hierarchy settings for new subscriptions.
DSE recommendation
Define and test the default management-group landing zone with approved policy and role inheritance.
Source facts
A newly added subscription normally joins the tenant’s root management group. Policy and role assignments at that root immediately affect the new subscription. Microsoft provides a hierarchy setting to select a different default management group for new subscriptions.
That lets an organization retain root-level governance while placing additional controls appropriate to new subscriptions on a separate landing group. Permissions to read and update hierarchy settings do not themselves grant other access throughout the hierarchy. Microsoft Learn.
Applicability
Identify the tenant root, current default group, proposed landing group, and inherited assignments. Keep the authority to change the hierarchy setting separate from the service owner’s permissions inside an individual subscription.
DSE recommendation
DSE recommends treating the default group as an onboarding control. Have platform and security owners approve its intended policies and access, then document the process for moving a subscription onward after onboarding. Preserve the old setting and review existing automation that assumes every new subscription initially appears under the root.
Verification
Using an approved test onboarding, inspect the subscription’s actual parent and effective governance. Confirm that intended controls apply and required onboarding work remains possible. Record the hierarchy setting, resulting placement, and any exceptions. Recheck this path after hierarchy or landing-group assignment changes rather than relying on the configured name alone.
Official references
Microsoft Learn: Protect your resource hierarchy – Azure Governance. Source retrieved September 9, 2026.
Review the official source
Protect your resource hierarchy - Azure Governance - Azure governance | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE