Azure service that audits and enforces how resources are configured, for example their location, SKU or tags, using definitions and assignments. It neither deploys resources nor controls access.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AZ-900SC-200AZ-400ALZ
Each book explains Azure Policy in context, with comparison tables and the common traps.
Terms in this definition
- SKU
The size or tier of a service, for example a VM size or the Premium tier of ACR.
- Image tagging
An Image Analysis feature producing single-word tags, each with a confidence score, for actions, scenery, objects and living things in an image.
Related terms
- Administrative units
Containers in Microsoft Entra ID that limit the reach of directory administrators to particular users, groups or devices. They are neither Azure Policy scopes nor cost groupings.
- Allowed locations
Built-in Azure Policy that rejects resources in any region missing from its list, making it the usual way to control where deployments go.
- Allowed locations for resource groups
Azure Policy definition that constrains only where resource groups are created; resources within those groups can still be placed in other regions.
- Allowed resource types
Deny-effect built-in Azure Policy that permits only the resource types it lists and blocks the rest.
- Allowed storage account SKUs
A built-in Azure Policy that limits the SKUs people may pick for a new storage account. It keeps redundancy and spending in check when a workload has no need for the pricier options.
- Allowed virtual machine size SKUs
Azure Policy that limits deployments to a chosen set of VM sizes.
- Append effect
Effect in Azure Policy whose field additions happen solely during create or update requests; already-deployed resources stay unremediated.
- AuditIfNotExists
Azure Policy effect that flags a resource as non-compliant if a related resource, identified by details.type and matching existenceCondition, is absent. It only reports and never deploys anything.