satycse06
New Contributor III

@szymon_dybczak Thanks for the response and well explanation.

I have another question related to vnet injection architecture. So as per you we can create a management group and include all the subscription in that management group and will apply the polices at root level. But what about network shall I assign each vnet for each of the subscription which will be part of the mangement group or a hub spoke architecture so that we can manage the network policies centrally like not allowing the public IP accessibility of databricks workspace