Azure Management Group Hierarchy — AZURE architecture diagram

About This Architecture

Azure Management Group hierarchy organizing a tenant root group into test-org, Platform, Landing zones, Decommissioned, and Sandbox branches for centralized governance. Platform management groups contain Security, Management, Identity, and Connectivity sub-groups, while Landing zones branch into Corp, Online, and Local with their own subscription tiers. This multi-level structure enables role-based access control, policy enforcement, and cost management across organizational units. Fork and customize this diagram on Diagrams.so to match your enterprise subscription strategy and compliance requirements.

People also ask

How should I structure Azure Management Groups for enterprise governance and subscription organization?

This diagram shows a proven Azure Management Group hierarchy with a tenant root group branching into Platform (Security, Management, Identity, Connectivity), Landing zones (Corp, Online, Local), and Sandbox tiers. This structure enables centralized policy enforcement, role-based access control, and cost management across organizational units while maintaining clear separation of concerns.

Azure Management Group Hierarchy

AzureintermediateManagement GroupsGovernanceLanding ZonesEnterprise ArchitectureRBAC
Domain: Cloud AzureAudience: Azure solutions architects designing tenant governance and subscription hierarchies
14 views0 favoritesPublic

Created by

July 6, 2026

Updated

September 19, 2026 at 2:46 PM

Type

network

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI

AI-generated. Verify before production use. Learn more

Report this diagram