DRAFT: ADR Management Group Governance Model

Summary

The University of Arkansas will use Azure Management Groups as the primary governance boundary for cloud environments.

Security, compliance, operational, and platform controls will be applied through Management Group inheritance rather than direct configuration of individual subscriptions whenever practical.

Body

Decision

Azure Management Groups will serve as the primary governance model for cloud environments.

Subscriptions will be placed into approved Management Group hierarchies and inherit required policies, guardrails, monitoring requirements, and governance controls through Management Group assignment.

Direct subscription-level governance configuration should be minimized in favor of inherited controls.

Technical Reasoning

Management Groups provide a scalable mechanism for enforcing governance consistently across multiple subscriptions.

Applying governance at the Management Group level reduces duplication, improves consistency, simplifies onboarding, and allows cloud standards to be implemented once and inherited across workloads.

This approach aligns with Azure-native governance capabilities and supports future growth of regulated and non-regulated workloads.

Consequences

New subscriptions must be placed within approved Management Group structures.

Standards and architecture patterns must define the Management Group placement required for supported workloads.

Governance controls will be managed centrally and inherited by subscriptions whenever possible.

Governance & Compliance

This ADR establishes the governance boundary for cloud environments.

Implementation details will be defined through standards and architecture patterns that assign subscriptions to appropriate Management Groups and inherit required controls.

Strategic Alignment

  • Consistency
  • Scalability
  • Automation
  • Operational Sustainability

Details

Details

Article ID: 2157
Created
Mon 8/31/26 1:50 AM
Modified
Tue 9/1/26 11:49 AM
Audience
Staff