Cloud

Azure Landing Zone Lab #1: Create Management Groups Step by Step

If you join a company as a Cloud Engineer, one of the first questions you should ask is:
“How is Azure structured?”

In this lab, you will create that structure yourself by building Azure Management Groups step by step, exactly the way real cloud environments are organized.


Expected Result:
By the end of this lab, you will see a clean Management Group hierarchy under your Azure tenant.

Prerequisites

  • An Azure account
  • Owner or Management Group Contributor permissions on the tenant root
  • Access to Azure Portal
Important:
If you do not have permissions at the tenant root level, you will NOT be able to create Management Groups.

Step 1: Open Management Groups in Azure Portal

  1. Go to https://portal.azure.com
  2. In the top search bar, type Management Groups
  3. Click Management Groups

You should now see a page showing your Tenant Root Group.

 

Expected Result:
A visual hierarchy with your Tenant Root Group at the top.

Step 2: Understand the Target Hierarchy

Before creating anything, understand what you are about to build.

Tenant Root Group
│
├── Platform
│   ├── Identity
│   ├── Management
│   └── Connectivity
│
└── LandingZones
    ├── Production
    └── Non-Production

This structure separates:

  • Platform services from workloads
  • Production from non-production environments

Step 3: Create the Platform Management Group

  1. In the Management Groups page, select Tenant Root Group
  2. Click + Add management group
  3. Name: Platform
  4. Management Group ID: platform
  5. Click Submit
Expected Result:
A new Management Group named Platform appears under Tenant Root Group.

Step 4: Create Platform Sub-Groups

Now create the core platform groups under Platform.

🚀 Cloud & DevOps is better when discussed, not Googled.

Join our Discord community to talk about real problems, tools, and lessons learned.

👉 Join the Discord Community

4.1 Create Identity

  1. Select Platform
  2. Click + Add management group
  3. Name: Identity
  4. ID: identity

4.2 Create Management

  1. Select Platform
  2. Name: Management
  3. ID: management

4.3 Create Connectivity

  1. Select Platform
  2. Name: Connectivity
  3. ID: connectivity
Expected Result:
Three Management Groups under Platform: Identity, Management, Connectivity.

Step 5: Create Landing Zones Management Group

  1. Select Tenant Root Group
  2. Click + Add management group
  3. Name: LandingZones
  4. ID: landingzones
Expected Result:
LandingZones appears next to Platform under Tenant Root Group.

Step 6: Create Production and Non-Production Groups

6.1 Production

  1. Select LandingZones
  2. Name: Production
  3. ID: prod

6.2 Non-Production

  1. Select LandingZones
  2. Name: Non-Production
  3. ID: nonprod
Expected Result:
LandingZones now contains Production and Non-Production groups.

Step 7: Verify the Final Hierarchy

Your final structure should look like this:

Tenant Root Group
│
├── Platform
│   ├── Identity
│   ├── Management
│   └── Connectivity
│
└── LandingZones
    ├── Production
    └── Non-Production
Success:
If your hierarchy matches this structure, Lab #1 is complete.

Optional: Create Management Groups Using Azure CLI

If you prefer CLI:

az account management-group create --name Platform
az account management-group create --name Identity --parent Platform
az account management-group create --name Management --parent Platform
az account management-group create --name Connectivity --parent Platform
az account management-group create --name LandingZones
az account management-group create --name Production --parent LandingZones
az account management-group create --name NonProduction --parent LandingZones

Why This Lab Matters for Cloud Engineers

Management Groups are not optional in real Azure environments.

  • Policies are applied here
  • RBAC is inherited from here
  • Subscriptions scale from here

If this layer is wrong, everything above it becomes hard to manage.


What’s Next?

In the next lab, you will:

  • Create Azure subscriptions
  • Attach them to Management Groups
  • Understand real subscription isolation

Next Lab:
Azure Landing Zone Lab #2: Create and Organize Subscriptions (Hands-On)

 

🚀 Cloud & DevOps is better when discussed, not Googled.

Join our Discord community to talk about real problems, tools, and lessons learned.

👉 Join the Discord Community

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button