SkillByAIOpen interactive version →

Lesson 2 / 25

Tenants, Subscriptions and Resource Groups

Place resources in the right level of the Azure management hierarchy.

Four levels of organisation

Everything you create in Azure is a resource (a VM, a storage account, a database). Resources live in a resource group: a logical folder whose members share a lifecycle, so deleting the group deletes everything in it. Resource groups live in a subscription, which is the billing and quota boundary and a common security boundary (many teams use separate subscriptions for dev, test and production). Subscriptions can be grouped under management groups, so a policy or role applied at the top flows down to every subscription below. Above all of this sits the Microsoft Entra tenant, the identity directory that holds your users, groups and app identities. A resource belongs to exactly one resource group, but it does not need to be in the same region as that group; the group's location only stores its metadata.

Creating and tagging a resource group

Tags are key-value labels used for cost reports and ownership. Put them on resource groups and resources from day one.

az account show --query "{name:name, id:id}" -o table      # which subscription am I in?
az account set --subscription "my-dev-subscription"

az group create \
  --name rg-shop-dev-cin \
  --location centralindia \
  --tags env=dev owner=team-shop costCenter=1234

# delete the whole environment when you are done
az group delete --name rg-shop-dev-cin --yes --no-wait

An office building

The tenant is the company, management groups are departments, subscriptions are each department's budget, and resource groups are project cupboards. When a project ends, you empty one cupboard instead of searching the whole building.

Quick check: You want every resource of a short-lived demo removed in one step. What is the best grouping?

  • One subscription per resource
  • Tag each resource and delete them one by one
  • Create a management group for the demo
  • Put all demo resources in one resource group and delete the group
Answer

Put all demo resources in one resource group and delete the group — A resource group shares a lifecycle; deleting it deletes every resource inside.