Built-in Azure Policy that rejects resources in any region missing from its list, making it the usual way to control where deployments go.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Allowed locations in context, with comparison tables and the common traps.
Terms in this definition
- Azure Policy
Azure service that audits and enforces how resources are configured, for example their location, SKU or tags, using definitions and assignments. It neither deploys resources nor controls access.
- region
A provider-defined grouping in VCF Automation of Supervisors that all share one NSX Local Manager; tenants consume its compute, storage and memory via quotas set per region.
- List
Permission on Key Vault secrets allowing a caller to enumerate those in a vault, though their values are not returned.
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.