An Azure Policy effect that stops any create or update request that would break the policy.
Also called Policy effect.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Deny in context, with comparison tables and the common traps.
Terms in this definition
- Azure Policy
Azure service that audits and enforces how resources are configured, for example their location, SKU or tags, using definitions and assignments. It neither deploys resources nor controls access.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
Related terms
- Access restrictions
Allow and deny rules for inbound App Service traffic, matched on IP range, service tag or subnet. They can, for instance, restrict an app to a corporate NAT's public addresses.
- AllowInternetOutBound
Built-in NSG outbound rule at priority 65001 that lets traffic reach the internet. A deny rule with a smaller priority number overrides it.
- Audit
Policy effect that lets a request proceed but flags the resource as non-compliant and logs a warning to the activity log. Microsoft suggests beginning there and later moving to something enforcing, like Deny.
- Azure Policy for Kubernetes
Admission control for Kubernetes based on Gatekeeper v3, installed as an AKS add-on or, on other clusters, an Arc extension. It acts as a webhook so that non-compliant pods are rejected by Azure Policy definitions set to Deny.
- Compute permissions
Access rules that live inside one Fabric engine and govern only queries run through it. They include T-SQL GRANT or DENY, masking and row-level security on a warehouse or SQL analytics endpoint, and DAX-based security in a semantic model.
- DCL
Data Control Language, the SQL statements GRANT, DENY and REVOKE that control permissions on database objects. Database administrators are the people who typically use them.
- DDL trigger
A trigger that responds to server or database events like CREATE, ALTER, DROP, GRANT, DENY or REVOKE. It is commonly used to record or prevent changes to the schema.
- Default elevation response
What Endpoint Privilege Management does when a user asks to run something elevated that no rule covers: it can deny, ask the user to confirm, or wait for support approval. Leaving it unset has the same effect as a denial.