Explanation: Policies can be applied to everything except the resource itself, and exclusion can specify everything except the Root Management Group. Box 1: Tenant Root Group, ManagementGroup1, Subscription1 and RG1 only Box 2: ManagementGroup1, Subscription1, RG1 and VM1 only Reference: https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/overview