You have a management group named MG1 that contains two subscriptions named Sub1 and Sub2. Sub1 contains a resource group named RG-Exception and a resource group named RG1 that hosts Microsoft Foundry resources. You need to assign an Azure policy to force new Foundry deployments in MG1 to use private endpoints. The solution must NOT restrict deployments in RG-Exception. How should you configure the policy?
Select an option, then click Submit answer.
- ○ Assign the policy to MG1 and exclude RG-Exception.
- ○ Assign the policy to Sub1 and RG-Exception.
- ○ Assign the policy to MG1 and RG-Exception.
- ○ Assign the policy to Sub1 and exclude RG-Exception.








