Skip to content
tezvyn:

Cloud Governance: Rules for Your Cloud Kingdom

Source: learn.microsoft.comMediumHow cards are made

Cloud Governance: Rules for Your Cloud Kingdom

Cloud governance is like city planning for your cloud, setting automated rules to prevent chaos. It's used to control costs by blocking expensive VMs and enforce security with required settings.

Why it exists

The cloud offers immense power and flexibility, but that freedom can lead to chaos. Without guardrails, teams can accidentally run up huge bills, create security vulnerabilities, or build inconsistent, hard-to-manage systems. Cloud governance exists to impose order on this potential chaos, ensuring resources are used securely, efficiently, and in line with business goals.

The mental model

Cloud governance is like setting the rules of the road for your cloud environment. It's not about micromanaging every driver (developer), but about installing traffic lights, speed limits, and guardrails (automated policies) to ensure everyone can move quickly and safely without causing accidents like security breaches or budget overruns. The goal is safe autonomy, not a restrictive police state.

How it works

Governance is a two-step process: definition and enforcement. First, you identify business risks (like overspending or data exfiltration) and define policies to mitigate them. This could be "no resources deployed outside the US" or "all storage accounts must have encryption enabled". Second, and most critically, you use the cloud provider's tools, like Azure Policy or AWS Service Control Policies, to automate the enforcement of these rules. These tools can either block non-compliant actions outright or flag them for review. Policies are typically applied hierarchically, from an entire organization down to a single resource.

When to use it

Use governance from day one, even for small projects. It's essential when you need to manage multiple teams or subscriptions, enforce security baselines (like those from CIS or NIST), control spending by restricting expensive resource types, or ensure consistent tagging for cost allocation and asset management. As your cloud footprint grows, effective governance becomes non-negotiable.

When not to use it

Governance is not for one-off, isolated experiments on a sandboxed account with no access to production data or significant budget. Overly restrictive policies in a pure R&D or learning environment can stifle innovation. The key is to match the level of governance to the risk level of the environment. A development sandbox needs fewer rules than a production environment handling financial data.

One canonical example

A company wants to control costs. They create a policy using Azure Policy that disallows the creation of the most expensive GPU-enabled virtual machine types in all development subscriptions. When a developer tries to deploy one of these VMs for a minor task, the deployment fails with an error message explaining the policy. This prevents accidental, massive bills while allowing for an exception process for legitimate use cases.

Interview question

What is the primary objective of implementing cloud governance within an organization?

  • a.To empower individual developers with complete freedom to provision any cloud resource.
  • b.To centralize all cloud resource deployment approvals through a single manual review board.
  • c.To ensure consistent security configurations and prevent unauthorized spending across cloud environments.Correct
  • d.To replace cloud provider native tools with custom-built solutions for resource management.
Why?

The card explicitly states that cloud governance imposes order to ensure resources are used securely and efficiently, specifically mentioning enforcing security with required settings and controlling costs by blocking expensive VMs. Option C directly reflects these core objectives, while other options describe either a lack of governance or misrepresent its automated and integrated nature.

Just read this? Test yourself on what you have been reading.

Read the original → learn.microsoft.com

You just looked this up. Could you explain it out loud?

That is the part interviews actually test. Tezvyn takes questions like this one and gives you what the interviewer is really checking, the answer that lands, and the mistake that ends the conversation, in the four minutes before your next meeting.

The iPhone app is on the way

We are building it. Until it lands, nothing here is held back from you: every interview card, your saved cards, streaks and the job board all work in Safari, plus hundreds of free practice quizzes of thirty questions each. Sign in and it all carries over to the app the day it arrives.

Want it as an icon? Tap Share at the bottom of Safari, then Add to Home Screen. It opens full screen and the cards you have read stay available offline.

Get it on Google PlayiPhone app coming soon

We are hiring for this. Open roles that interview on cloud — each one lists the topics its interview covers.

See open roles