Skip to main content

Subscription

A billing and access-management boundary in Azure that groups resource groups together, tied to an Azure AD/Entra ID tenant, and used to apply spending limits, quotas, and top-level access policies.

Subscription

A Subscription is the container above resource groups — it's where billing, quotas, and top-level RBAC assignments live.

Why It Matters in Production

Razorpay runs separate subscriptions for razorpay-prod-sub and razorpay-nonprod-sub so a runaway dev/test cost spike can never touch the production billing account or quota limits.

Bash
az account list --output table
az account set --subscription "razorpay-prod-sub"
Common Mistake

Assuming subscriptions provide network isolation — they don't. Use VNets and NSGs for that; subscriptions are a billing and access boundary only.

Frequently Asked Questions

How does an Azure Subscription relate to a resource group and a tenant?

The hierarchy runs tenant (Azure AD/Entra ID, your organization's identity boundary) → subscription (billing and top-level access/quota boundary) → resource group (a logical container for related resources) → individual resources. A single tenant can contain multiple subscriptions — common for separating production from non-production billing, or isolating cost centers per department — and a subscription can contain many resource groups.

What's a common mistake in how organizations structure Azure Subscriptions?

Putting everything into one subscription for simplicity, which then makes it hard to apply different governance policies, cost allocation, or hard spending limits per team or environment, and creates a single blast radius for subscription-level quota exhaustion. Microsoft's Cloud Adoption Framework recommends a multi-subscription landing zone design (e.g., separate subscriptions per environment or business unit) precisely to avoid this, though it adds management overhead that's not worth it for small orgs.