nerdexam
Microsoft

AZ-500 · Question #216

Drag and Drop Question You have five Azure subscriptions linked to a single Azure Active Directory (Azure AD) tenant. You create an Azure Policy initiative named SecurityPolicyInitiative1. You…

The correct answer is Create an Azure Blueprints definition.; Publish an Azure Blueprints version.; Assign an Azure blueprint. Azure Blueprints is the correct tool because it allows you to package policy initiatives AND role assignments together as a single deployable unit that can be enforced when new resource groups are created. The correct sequence is: first Create an Azure Blueprints definition (to…

Submitted by yaw92· Mar 6, 2026Manage Identity and Governance - Implement and manage Azure governance solutions including Azure Blueprints, Policy, and role-based access control (AZ-104 / AZ-500)

Question

Drag and Drop Question You have five Azure subscriptions linked to a single Azure Active Directory (Azure AD) tenant. You create an Azure Policy initiative named SecurityPolicyInitiative1. You identify which standard role assignments must be configured on all new resource groups. You need to enforce SecurityPolicyInitiative1 and the role assignments when a new resource group is created. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Answer:

Exhibits

AZ-500 question #216 exhibit 1
AZ-500 question #216 exhibit 2

Answer Area

Drag items

Publish an Azure Blueprints versionAssign an Azure blueprint.Create a policy assignment.Create a custom role-based access control (RBAC) role.Create a dedicated management subscription.Create an Azure Blueprints definition.Create an initiative assignment.

Correct arrangement

  • Create an Azure Blueprints definition.
  • Publish an Azure Blueprints version.
  • Assign an Azure blueprint.

Explanation

Azure Blueprints is the correct tool because it allows you to package policy initiatives AND role assignments together as a single deployable unit that can be enforced when new resource groups are created. The correct sequence is: first Create an Azure Blueprints definition (to bundle SecurityPolicyInitiative1 and the RBAC role assignments as artifacts), then Publish an Azure Blueprints version (blueprints must be published/versioned before they can be assigned), and finally Assign an Azure blueprint (to enforce it across subscriptions so it triggers on new resource group creation). Blueprints uniquely solve this problem because they can enforce both policy initiatives and role assignments simultaneously in a locked, repeatable manner.

Topics

#Azure Blueprints#Azure Policy#RBAC#Governance

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice