On a deployment stack, DenyDelete or DenyWriteAndDelete applies deny assignments to the managed resources that bind every principal, Owners too, apart from any excluded.
Also called DenyDelete, DenyWriteAndDelete.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Deny settings in context, with comparison tables and the common traps.
Terms in this definition
- Deployment stack
An Azure resource that rolls out a Bicep or ARM template and treats everything it creates as one managed group. Resources dropped from the template can be removed or simply released, and deny settings can guard the rest against changes.
- Deny assignments
Azure RBAC entries that block actions even where a role assignment allows them. Once only Azure services such as deployment stacks made them; users can now create them too (New-AzDenyAssignment or az role deny-assignment create), covering write, delete and action operations but not groups.
- Principal
A user, group or service principal: anything that can receive a privilege grant.
Related terms
- Azure Deployment Stack Owner
Built-in role covering full deployment stack management, deny settings included.