You have the Azure management groups shown in the following table:
You add Azure subscriptions to the management groups as shown in the following table:
You create the Azure policies shown in the following table:
Choose all that apply:
Virtual networks are not allowed at the root and is inherited. Deny overrides allowed.
Virtual Machines can be created on a Management Group provided the user has the required RBAC permissions.
Subscriptions can be moved between Management Groups provided the user has the required RBAC permissions.