Summary
The University of Arkansas will use Azure Management Groups as the primary governance boundary for cloud environments.
Security, compliance, operational, and platform controls will be applied through Management Group inheritance rather than direct configuration of individual subscriptions whenever practical.
Body
Decision
Azure Management Groups will serve as the primary governance model for cloud environments.
Subscriptions will be placed into approved Management Group hierarchies and inherit required policies, guardrails, monitoring requirements, and governance controls through Management Group assignment.
Direct subscription-level governance configuration should be minimized in favor of inherited controls.
Technical Reasoning
Management Groups provide a scalable mechanism for enforcing governance consistently across multiple subscriptions.
Applying governance at the Management Group level reduces duplication, improves consistency, simplifies onboarding, and allows cloud standards to be implemented once and inherited across workloads.
This approach aligns with Azure-native governance capabilities and supports future growth of regulated and non-regulated workloads.
Consequences
New subscriptions must be placed within approved Management Group structures.
Standards and architecture patterns must define the Management Group placement required for supported workloads.
Governance controls will be managed centrally and inherited by subscriptions whenever possible.
Governance & Compliance
This ADR establishes the governance boundary for cloud environments.
Implementation details will be defined through standards and architecture patterns that assign subscriptions to appropriate Management Groups and inherit required controls.
Strategic Alignment
- Consistency
- Scalability
- Automation
- Operational Sustainability